PT-2022-17098 · Liferay · Liferay Portal+1

Jakub Zoczek

·

Published

2022-03-02

·

Updated

2024-01-31

·

CVE-2022-25146

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.4.3.4 through 7.4.3.8 Liferay DXP 7.4 before update 5
Description The issue concerns the Remote App module, which fails to verify if the origin of received event messages matches the Remote App's origin. This allows attackers to potentially exfiltrate the CSRF token by sending a crafted event message.
Recommendations For Liferay Portal versions 7.4.3.4 through 7.4.3.8, update to a version outside of this range to resolve the issue. For Liferay DXP 7.4 before update 5, apply update 5 or later to fix the problem.

Fix

Origin Validation Error

Weakness Enumeration

Related Identifiers

BIT-LIFERAY-2022-25146
CVE-2022-25146
GHSA-GHW5-998M-VW4W

Affected Products

Liferay Dxp
Liferay Portal