-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the Account Settings page embedding hashed passwords in HTML output. In Liferay's architecture:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.liferay.portal:release.portal.bom | maven | >= 7.4.3.76, < 7.4.3.100 | 7.4.3.100 |
| com.liferay.portal:release.dxp.bom | maven | >= 2023.Q3, < 2023.Q3.5 | 2023.Q3.5 |
| com.liferay.portal:release.dxp.bom |
| maven |
| >= 7.4.0, <= 7.4.13.u92 |
Ongoing coverage of React2Shell