CVE Vulnerabilities

CVE-2020-15840

Published: Sep 24, 2020 | Modified: May 13, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property portlet.resource.id.banned.paths.regexp can be bypassed with doubled encoded URLs.

Affected Software

Name Vendor Start Version End Version
Digital_experience_platform Liferay 7.0 (including) 7.0 (including)
Digital_experience_platform Liferay 7.1 (including) 7.1 (including)
Digital_experience_platform Liferay 7.2 (including) 7.2 (including)
Liferay_portal Liferay * 7.3.1 (excluding)
Liferay_portal Liferay 6.2 (including) 6.2 (including)

References