House of Rabbit 的核心思想随着ASLR、PIE、NX等防护机制的普及,传统的栈溢出和代码注入变得举步维艰。攻击者的焦点逐渐转向了堆利用。glibc的堆分配器(ptmalloc2)特别复杂性,是漏洞利用的“富矿”。House of Rabbit技术是通过一个可控的堆溢出或写原语,伪造一个堆块,然后利用malloc_consolidate向前合并机制,通过堆溢出或其他内存破坏漏洞,伪造
A vulnerability marked as problematic has been reported in Liferay Portal and DXP. Affected is an unknown function of the component Publications. This manipulation of the argument _com_liferay_change_tracking_web_portlet_PublicationsPortlet_ctCollectionId causes authorization bypass.
The identification of this vulnerability is CVE-2025-62244. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Liferay Portal and DXP. Affected by this issue is some unknown functionality of the component Publications. Performing manipulation of the argument _com_liferay_change_tracking_web_portlet_PublicationsPortlet_value results in incorrect authorization.
This vulnerability is identified as CVE-2025-62243. The attack can be initiated remotely. There is not any exploit available.