GHSA-rpj9-pc39-h8j8

Suggest an improvement
Source
https://github.com/advisories/GHSA-rpj9-pc39-h8j8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rpj9-pc39-h8j8/GHSA-rpj9-pc39-h8j8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rpj9-pc39-h8j8
Aliases
  • CVE-2011-1571
Published
2022-05-13T01:25:11Z
Modified
2025-07-15T20:12:17Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Liferay Portal vulnerable to arbitrary command injection
Details

Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors.

Database specific
{
    "cwe_ids":  [
        "CWE-77"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-07-15T19:23:37Z",
    "nvd_published_at":  "2011-05-07T19:55:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / com.liferay.portal:portal-service

Package

Name
com.liferay.portal:portal-service
View open source insights on deps.dev
Purl
pkg:maven/com.liferay.portal/portal-service

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Fixed
6.0.6-ga

Affected versions

5.*
5.2.3
6.*
6.0.2
6.0.3
6.0.4
6.0.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rpj9-pc39-h8j8/GHSA-rpj9-pc39-h8j8.json"