CVE-2020-24554: High severity liferay 7.4 ga vulnerability
Published Sep 1, 2020
·Updated
The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, which allows remote attackers to perform a denial of service attack by making repeated requests for pages that do not exist.
Affected Software
1 affected component
Liferay Liferay Portal<7.3.3
Event History
Sep 1, 2020
CVE Published
via MITRE·01:49 PM
Data Sourced
via MITRE·01:49 PM
Description
Frequently Asked Questions
1
What is the impact of CVE-2020-24554 vulnerability?
The vulnerability allows remote attackers to perform a denial of service attack by making repeated requests for pages that do not exist.
2
How can I mitigate CVE-2020-24554 vulnerability?
Update Liferay Portal to version 7.3.3 or later to limit the number of URLs resulting in a 404 error that is recorded.