{"id":"GHSA-mg53-xr8m-86hw","summary":"Open Redirect in Liferay Portal","details":"The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, which allows remote attackers to perform a denial of service attack by making repeated requests for pages that do not exist.","aliases":["CVE-2020-24554"],"modified":"2023-11-01T04:52:36.227744Z","published":"2021-05-07T15:54:54Z","database_specific":{"nvd_published_at":"2020-09-01T14:15:00Z","cwe_ids":["CWE-601"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-05-05T19:14:04Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-24554"},{"type":"WEB","url":"https://portal.liferay.dev/learn/security/known-vulnerabilities"},{"type":"WEB","url":"https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/119784956"}],"affected":[{"package":{"name":"com.liferay.portal:release.portal.bom","ecosystem":"Maven","purl":"pkg:maven/com.liferay.portal/release.portal.bom"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.3.3"}]}],"versions":["7.0.6","7.0.6-1","7.0.6-2","7.1.0","7.1.1","7.1.2","7.1.3","7.1.3-1","7.2.0","7.2.1","7.2.1-1","7.3.0","7.3.0-1","7.3.1","7.3.1-1","7.3.2","7.3.2-1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-mg53-xr8m-86hw/GHSA-mg53-xr8m-86hw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}