-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability description explicitly identifies Java2WsddTask._format as the entry point for XXE attacks. The CWE-611 classification confirms this is an XML external entity handling flaw. While no code was provided, the advisory's specificity about the method name and its role in XML processing (common in WSDD generation tasks) strongly indicates insecure XML parser configuration in this function. The affected package com.liferay.portal:com.liferay.util.java aligns with the class's likely location.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.liferay.portal:com.liferay.util.java | maven | < 14.0.0 | 14.0.0 |
| com.liferay.portal:release.portal.bom | maven | < 7.4.3.8 | 7.4.3.8 |
| com.liferay.portal:release.dxp.bom |
| maven |
| >= 7.3.0, < 7.3.10.u12 |
| 7.3.10.u12 |
| com.liferay.portal:release.dxp.bom | maven | >= 7.4.0, < 7.4.13.u4 | 7.4.13.u4 |
| com.liferay.portal:release.dxp.bom | maven | < 7.2.10.fp20 | 7.2.10.fp20 |
Ongoing coverage of React2Shell