Liferay Portal does not limit the depth of a GraphQL queries
High severity
GitHub Reviewed
Published
Jun 16, 2025
to the GitHub Advisory Database
•
Updated Jun 16, 2025
Package
Affected versions
< 5.0.103
Patched versions
5.0.103
Description
Published by the National Vulnerability Database
Jun 16, 2025
Published to the GitHub Advisory Database
Jun 16, 2025
Reviewed
Jun 16, 2025
Last updated
Jun 16, 2025
Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and 7.2 fix pack 8 through fix pack 20 does not limit the depth of a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing complex queries.
References