maven package report

Is com.liferay.portal:release.dxp.bom safe?

100 known vulnerabilities, worst severity CRITICAL.

cvss
9.6

how bad it is if exploited, out of 10

epss
0.20%

chance of exploitation in the next 30 days

xyz score
4.0

CyberXYZ composite, out of 10

fig. 01 — GHSA-chj2-4vg7-hhg3, the advisory selected below

// advisories

GHSA-chj2-4vg7-hhg3

CRITICALCVE-2024-8980

The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA through fix pack 28, 7.0 GA through fix pack 102 and 6.2 GA through fix pack 173 does not sufficiently protect against Cross-Site Request Forgery (CSRF) attacks, which allows remote attackers to execute arb

Affected
>= 7.3.0-GA, < 7.3.10.u36, >= 7.0.0-GA, <= 7.0.10.fp102, >= 2023.Q3.1, < 2023.Q3.5, >= 7.1.0-GA, <= 7.1.10.fp28, >= 7.4.0-GA, <= 7.4.13.u92, >= 7.2.0.GA, <= 7.2.10.fp20
Fixed in
7.3.10.u36
Weakness
CWE-352
Published
2024-10-22
Source
github

GHSANVDMITREreference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 00:56 UTC. The most recent advisory here was published 2025-08-12. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is com.liferay.portal:release.dxp.bom safe? maven package security report | CyberXYZ