<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>Sonatype Vulnerability com.liferay.portal.impl@42.0.0?type=jar</title>
  <link rel="self" href="https://uat.liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=121514148" />
  <subtitle>Sonatype Vulnerability com.liferay.portal.impl@42.0.0?type=jar</subtitle>
  <id>https://uat.liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=121514148</id>
  <updated>2026-08-02T05:40:20Z</updated>
  <dc:date>2026-08-02T05:40:20Z</dc:date>
  <entry>
    <title>Sonatype Vulnerability com.liferay.portal.impl@42.0.0?type=jar</title>
    <link rel="alternate" href="https://uat.liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121514147" />
    <author>
      <name>Kevin Matthews</name>
    </author>
    <id>https://uat.liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121514147</id>
    <updated>2022-09-14T14:01:32Z</updated>
    <published>2022-09-13T14:15:18Z</published>
    <summary type="html">&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Have liferay done Sonatype scanning on the latest build GA40 releases
  as we ran a sonatype scan for the following vulnerability on component&lt;/p&gt;
&lt;table&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;com.liferay.portal.impl@42.0.0?type=jar. &lt;strong&gt;Will liferay
          be providing an upgrade path for this vulenerability?&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;Below are Sonatype Scan assesment:&lt;/p&gt;
&lt;p&gt;
  &lt;strong&gt;Recommended Version(s): &lt;/strong&gt;No recommended versions are
  available for the current component.&lt;br /&gt;
  &lt;strong&gt;Explanation: &lt;/strong&gt;Liferay Portal contains a Cross-site
  Scripting (XSS) vulnerability. The `getCurrentCompleteURL` and
  `getCurrentURL` methods in `PortalImpl.class` do not properly escape
  the URL string. An attacker can exploit this by including malicious
  HTML code in the URL string that would then be parsed and executed.&lt;br /&gt;
  &lt;strong&gt;Detection: &lt;/strong&gt;The application is vulnerable by using
  this component.&lt;br /&gt;
  &lt;strong&gt;Recommendation: &lt;/strong&gt;There is no non vulnerable version of
  this component/package. We recommend investigating alternative
  components or a potential mitigating control.&lt;br /&gt;
  &lt;strong&gt;Threat Vectors: &lt;/strong&gt;CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Kevin&lt;/p&gt;</summary>
    <dc:creator>Kevin Matthews</dc:creator>
    <dc:date>2022-09-13T14:15:18Z</dc:date>
  </entry>
</feed>
