CVE-2021-29051: XSS
Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal 7.2.1 through 7.3.5, and Liferay DXP 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the comliferayassetpublisherwebportletAssetPublisherPortletINSTANCEXXXXXXXXXXXXassetEntryId parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.fp1 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp10 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.1.10.fp21 - Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.3.6 - Upgrade
Upgrade
Liferay Portal 7.2 (Asset module Asset Publisher)to a version that resolves this vulnerability.Fixed in 7.2Patch fix pack 10 - Upgrade
Upgrade
Liferay Portal 7.3 (Asset module Asset Publisher)to a version that resolves this vulnerability.Fixed in 7.3Patch fix pack 1
Event History
Frequently Asked Questions
What is the severity of CVE-2021-29051?
The severity of CVE-2021-29051 is medium.
How does CVE-2021-29051 affect Liferay Portal and Liferay DXP?
CVE-2021-29051 affects Liferay Portal versions 7.2.1 through 7.3.5, and Liferay DXP versions 7.1 before fix pack 21, 7.2 before fix pack 10, and 7.3 before fix pack 1.
What is the vulnerability in CVE-2021-29051?
The vulnerability in CVE-2021-29051 is a cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app.
How can CVE-2021-29051 be exploited?
CVE-2021-29051 can be exploited by remote attackers to inject arbitrary web script or HTML via the _com_liferay_asset parameter.
Where can I find more information about CVE-2021-29051?
More information about CVE-2021-29051 can be found at the following references: [http://liferay.com](http://liferay.com), [https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120743580](https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120743580)