CVE Vulnerabilities

CVE-2023-33950

Inefficient Regular Expression Complexity

Published: May 24, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an excessive amount of server resources via crafted request URLs.

Weakness

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Affected Software

NameVendorStart VersionEnd Version
Digital_experience_platformLiferay7.4-update48 (including)7.4-update48 (including)
Digital_experience_platformLiferay7.4-update76 (including)7.4-update76 (including)
Liferay_portalLiferay7.4.3.48 (including)7.4.3.76 (including)

Potential Mitigations

References