Skip to main content

Tags Xxe

Liferay: XML External Entity vulnerability in OpenID component

Published on Jan 1, 2016 in , ,

Description

Liferay supports OpenID login which was found to make use of a version of openid4java that is vulnerable to XML External Entity (XXE) attacks.

Impact

Abuse of the XXE vulnerability can (at least) lead to local file disclosure, server-side request forgery (SSRF) and denial of service. This vulnerability was abused to read local files on the web server that the web application had access to.

Read more about Liferay: XML External Entity vulnerability in OpenID component