CVE-2023-33950
published 2023-05-24CVE-2023-33950: Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.92%
56.5th percentile
Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an excessive amount of server resources via crafted request URLs.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | digital_experience_platform | — | — |
| liferay | dxp | 7.4.13.u48 – 7.4.13.u76 | — |
| liferay | liferay_portal | 7.4.3.48 – 7.4.3.76 | — |
| liferay | portal | 7.4.3.48 – 7.4.3.76 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Liferay Portal has Inefficient Regular Expression
osv·2023-05-24
CVE-2023-33950 [MEDIUM] Liferay Portal has Inefficient Regular Expression
Liferay Portal has Inefficient Regular Expression
Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an excessive amount of server resources via crafted request URLs.
GHSA
Liferay Portal has Inefficient Regular Expression
ghsa·2023-05-24
CVE-2023-33950 [MEDIUM] CWE-1333 Liferay Portal has Inefficient Regular Expression
Liferay Portal has Inefficient Regular Expression
Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an excessive amount of server resources via crafted request URLs.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-24
Published