-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from client-controlled maxFileSize parameter being trusted without server-side validation. While exact function names aren't explicitly disclosed in advisories, Liferay's architecture patterns suggest:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.liferay.portal:release.portal.bom | maven | < 7.4.3.16 | 7.4.3.16 |
Ongoing coverage of React2Shell