CVE-2020-13444: Liferay Portal
Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.
Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers.
Affected products
- Liferay Liferay Portal: version 7.1 only; version 7.1.1 only; version 7.2 only; version 7.3 only
Published 2020-06-10. Last modified 2026-06-17.