Search Results

Sort By
Capability
Feature
Deployment Approach
Elasticsearch and Liferay Enterprise Search Security Advisory: CVE-2018-3831
authorEmailAddress: tibor.lipusz@liferay.com, authorName: Tibor Lipusz, content: CVE-2018-3831 reports that, "Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings...
Excluding User Groups Not Part of the BaseDN In LDAP Import
authorEmailAddress: christopher.lui@liferay.com, authorName: Christopher Lui, content: This article is a legacy article. It applies to previous versions of the Liferay product. While the article is no longer maintained, the information may still be applicable. In older versions of Liferay Portal...
Apache Struts 2 Vulnerability: CVE-2017-9805 and CVE-2017-12611 - REST XStream FreeMarker
authorEmailAddress: tibor.lipusz@liferay.com, authorName: Tibor Lipusz, content: The following Common Vulnerabilities and Exposures (CVE) have been reported for Apache Struts 2: CVE-2017-9805 CVE-2017-12611 CVE-2018-1327 - REST XStream FreeMarker CVE-2018-11776 How are Liferay DXP (both 7.0 and...
JSESSIONID Changes as Part of Liferay Security
authorEmailAddress: justin.choi@liferay.com, authorName: Justin Choi, content: This article documents Liferay's position regarding the Session Identifier (JSESSIONID), including how and why a new JSESSIONID is generated.  Resolution Customers doing their own security scan of the Liferay platform...