Liferay Portal Vulnerable to Denial of Service in Kaleo Forms Admin
High severity
GitHub Reviewed
Published
Sep 4, 2025
to the GitHub Advisory Database
•
Updated Sep 4, 2025
Package
Affected versions
< 5.0.29
Patched versions
5.0.29
Description
Published by the National Vulnerability Database
Sep 4, 2025
Published to the GitHub Advisory Database
Sep 4, 2025
Reviewed
Sep 4, 2025
Last updated
Sep 4, 2025
Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not restrict the saving of request parameters in the portlet session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP request.
References