Lucene search

K
osvGoogleOSV:CVE-2020-15840
HistorySep 24, 2020 - 3:15 p.m.

CVE-2020-15840

2020-09-2415:15:14
Google
osv.dev
2

6.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.1%

In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property ‘portlet.resource.id.banned.paths.regexp’ can be bypassed with doubled encoded URLs.

6.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.1%

Related for OSV:CVE-2020-15840