CVE-2020-24554: Liferay Portal

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, which allows remote attackers to perform a denial of service attack by making repeated requests for pages that do not exist.

Affected products

  • Liferay Liferay Portal: before 7.3.3 (fixed in 7.3.3)

Published 2020-09-01. Last modified 2026-06-17.