CVE-2023-33950Regex Denial of Service in DXP

Severity
7.5HIGHNVD
CNA6.5
EPSS
0.6%
top 30.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 24

Description

Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an excessive amount of server resources via crafted request URLs.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

CVEListV5liferay/portal7.4.3.487.4.3.76
NVDliferay/liferay_portal7.4.3.487.4.3.76
CVEListV5liferay/dxp7.4.13.u487.4.13.u76

🔴Vulnerability Details

3
CVEList
CVE-2023-33950: Pattern Redirects in Liferay Portal 72023-05-24
OSV
Liferay Portal has Inefficient Regular Expression2023-05-24
GHSA
Liferay Portal has Inefficient Regular Expression2023-05-24
CVE-2023-33950 — Regex Denial of Service in Liferay DXP | cvebase