Denial of service in Liferay Enterprise Portal - #VU8547
Published: September 21, 2017
Liferay Enterprise Portal
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to errors in AggregateFilter, MinifierFilter and DynamicCSSFilter components. A remote attacker can use a specially crafted URL to consume all available disk space on the system and cause denial of service (DoS) conditions.
Remediation
https://sourceforge.net/projects/liferay-patches/files/7.0.3%20GA4/
https://github.com/community-security-team/liferay-portal/compare/7.0.3-ga4...7.0.3-CST-7028.patch