Liferay 6.2.3 CE GA4 OpenID XXE Injection
Posted by deepcore on June 4, 2016 – 8:33 pm
Liferay supports OpenID login which was found to make use of a version of openid4java that is vulnerable to XML External Entity (XXE) attacks. Liferay versions 6.2.3 CE GA4 and earlier are affected.
Post a reply
You must be logged in to post a comment.