PT-2022-17098 · Liferay · Liferay Portal+1
Jakub Zoczek
·
Published
2022-03-02
·
Updated
2024-01-31
·
CVE-2022-25146
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Liferay Portal versions 7.4.3.4 through 7.4.3.8
Liferay DXP 7.4 before update 5
Description
The issue concerns the Remote App module, which fails to verify if the origin of received event messages matches the Remote App's origin. This allows attackers to potentially exfiltrate the CSRF token by sending a crafted event message.
Recommendations
For Liferay Portal versions 7.4.3.4 through 7.4.3.8, update to a version outside of this range to resolve the issue.
For Liferay DXP 7.4 before update 5, apply update 5 or later to fix the problem.
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Liferay Dxp
Liferay Portal