<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>Liferay Community Security Team - Notifications for new vulnerabilities</title>
  <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/rss" />
  <subtitle>Liferay Community Security Team - Notifications for new vulnerabilities</subtitle>
  <entry>
    <title>CST-SA: LPS-33764 Various XSS Issues in Liferay 6.1.1</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/23269375" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/23269375</id>
    <updated>2013-04-02T19:48:25Z</updated>
    <published>2013-04-02T19:48:25Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2013-04-02T19:48:25Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-31750 Non-secure cookie LFR_SESSION_STATE_XXXXXX is created when connected over HTTPS</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/23267722" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/23267722</id>
    <updated>2013-04-02T19:08:46Z</updated>
    <published>2013-04-02T19:08:46Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2013-04-02T19:08:46Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-31090 DLFileVersionServiceImpl.getLatestFileVersion(long) doesn't have permission check</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/23267639" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/23267639</id>
    <updated>2013-04-02T19:04:21Z</updated>
    <published>2013-04-02T19:04:21Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2013-04-02T19:04:21Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-31063 XSS vulnerability with swfuploader</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/23267592" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/23267592</id>
    <updated>2013-04-02T19:00:35Z</updated>
    <published>2013-04-02T19:00:35Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2013-04-02T19:00:35Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-30940 cdn_host parameter allows JS injection (XSS)</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/23267505" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/23267505</id>
    <updated>2013-04-02T18:54:26Z</updated>
    <published>2013-04-02T18:54:26Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2013-04-02T18:54:26Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-29872 Organization admin of sub organization can export users of parent organization</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/23267429" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/23267429</id>
    <updated>2013-04-02T18:50:18Z</updated>
    <published>2013-04-02T18:50:18Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2013-04-02T18:50:18Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-29341 Posting messages in foreign Message Boards</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/23266249" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/23266249</id>
    <updated>2013-04-02T18:41:04Z</updated>
    <published>2013-04-02T18:41:04Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2013-04-02T18:41:04Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-29268 Simple DOS attack on PortletPreferences</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/23265789" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/23265789</id>
    <updated>2013-04-02T18:12:34Z</updated>
    <published>2013-04-02T18:12:34Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2013-04-02T18:12:34Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-30437 Users without permission can create folders/files in the root folder</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/17982621" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/17982621</id>
    <updated>2012-11-16T17:40:15Z</updated>
    <published>2012-11-16T17:40:15Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2012-11-16T17:40:15Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-28550 Able to view any journal structure/template's source</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/17982454" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/17982454</id>
    <updated>2012-11-16T17:35:03Z</updated>
    <published>2012-11-16T17:27:55Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2012-11-16T17:27:55Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-30796 Delete any file on the server (Knowledge Base)</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/17982378" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/17982378</id>
    <updated>2012-11-16T17:22:07Z</updated>
    <published>2012-11-16T17:22:07Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2012-11-16T17:22:07Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-30093 Organization administrators can change an omni-admin's password</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/17393210" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/17393210</id>
    <updated>2012-10-23T16:27:53Z</updated>
    <published>2012-10-23T16:27:53Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2012-10-23T16:27:53Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-29338 XSS in group membership requests</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/17393143" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/17393143</id>
    <updated>2012-10-23T16:24:22Z</updated>
    <published>2012-10-23T16:24:22Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2012-10-23T16:24:22Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-29148 Private announcements can be viewed through announcement edit</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/17393065" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/17393065</id>
    <updated>2012-10-23T16:19:12Z</updated>
    <published>2012-10-23T16:19:12Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2012-10-23T16:19:12Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-29061 test@liferay.com created by setupwizard even when different user specified</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/17392938" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/17392938</id>
    <updated>2012-10-23T16:13:08Z</updated>
    <published>2012-10-23T16:13:08Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2012-10-23T16:13:08Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-30586 Able to delete any user by created URL</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/17392788" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/17392788</id>
    <updated>2012-10-23T16:04:49Z</updated>
    <published>2012-10-23T16:04:49Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2012-10-23T16:04:49Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-28934 Delete any file on the server (Wiki)</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/15175176" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/15175176</id>
    <updated>2012-10-23T15:44:15Z</updated>
    <published>2012-07-31T20:43:12Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2012-07-31T20:43:12Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-28836 Directory traversal with document conversion</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/15045237" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/15045237</id>
    <updated>2012-10-23T15:44:53Z</updated>
    <published>2012-07-26T14:09:39Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2012-07-26T14:09:39Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-28423 Delete any file on the server</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/14774006" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/14774006</id>
    <updated>2012-10-23T15:49:03Z</updated>
    <published>2012-07-09T21:31:45Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2012-07-09T21:31:45Z</dc:date>
  </entry>
  <entry>
    <title>CST-SA: LPS-26930 Reconfigure Liferay to use a remote cache</title>
    <link rel="alternate" href="http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/14773954" />
    <author>
      <name>James Falkner</name>
    </author>
    <id>http://www.liferay.com/de/community/security-team/known-vulnerabilities/-/asset_publisher/T8Ei/content/id/14773954</id>
    <updated>2012-10-23T15:48:44Z</updated>
    <published>2012-07-09T21:23:55Z</published>
    <summary type="html" />
    <dc:creator>James Falkner</dc:creator>
    <dc:date>2012-07-09T21:23:55Z</dc:date>
  </entry>
</feed>

