CVE-2020-15840: Medium severity liferay 7.4 ga vulnerability
In Liferay Portal before 7.3.1, com.liferay.portal:com.liferay.portal.impl before 7.1.3 and 7.4.0, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.
Other sources
In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-15840?
CVE-2020-15840 has a medium severity rating due to potential security risks related to URL bypasses.
How do I fix CVE-2020-15840?
To mitigate CVE-2020-15840, upgrade to Liferay Portal version 7.3.1 or later, or ensure that the property 'portlet.resource.id.banned.paths.regexp' is configured correctly.
What are the affected versions for CVE-2020-15840?
CVE-2020-15840 affects Liferay Portal versions before 7.3.1, Liferay DXP 7.0, 7.1, and 7.2, as well as Liferay 6.2 EE.
What does the CVE-2020-15840 vulnerability exploit?
CVE-2020-15840 exploits the ability to bypass the 'portlet.resource.id.banned.paths.regexp' property with double encoded URLs.
Is CVE-2020-15840 a critical vulnerability?
CVE-2020-15840 is not classified as critical, but it poses significant risks if left unaddressed.