PT-2024-17388 · Liferay · Liferay Portal +1
Liferay
+1
·
Published
2024-12-17
·
Updated
2024-12-18
·
CVE-2024-11993
6.1
Medium
Base vector | Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Liferay Portal versions 7.1.0 through 7.4.3.38
Liferay DXP versions 7.4 GA through update 38
Liferay DXP versions 7.3 GA through update 36
Liferay DXP versions 7.2 GA through fix pack 20
Liferay DXP versions 7.1 GA through fix pack 28
Description:
A reflected cross-site scripting (XSS) issue allows remote attackers to execute arbitrary web script or HTML via the Dispatch name field. This enables the execution of malicious scripts, potentially leading to unauthorized actions on the affected system.
Recommendations:
For Liferay Portal versions 7.1.0 through 7.4.3.38, update to a version outside of this range to mitigate the risk.
For Liferay DXP versions 7.4 GA through update 38, apply update 39 or later.
For Liferay DXP versions 7.3 GA through update 36, apply update 37 or later.
For Liferay DXP versions 7.2 GA through fix pack 20, apply fix pack 21 or later.
For Liferay DXP versions 7.1 GA through fix pack 28, apply fix pack 29 or later.
As a temporary workaround, consider restricting access to the Dispatch name field until a patch is available.
Fix
RCE
XSS
Weakness Enumeration
Related Identifiers
Affected Products
References · 12
- https://osv.dev/vulnerability/GHSA-4hxr-28mv-q729 · Vendor Advisory
- https://osv.dev/vulnerability/CVE-2024-11993 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-11993 · Security Note
- https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-11993 · Vendor Advisory
- https://github.com/liferay/liferay-portal⭐ 2171 🔗 3693 · Note
- https://t.me/cvedetector/13134 · Telegram Post
- https://twitter.com/VulmonFeeds/status/1869155784854057179 · Twitter Post
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-11993 · Note
- https://t.me/cvenotify/104623 · Telegram Post
- https://twitter.com/CVEnew/status/1869123011703439768 · Twitter Post
- https://twitter.com/transilienceai/status/1869250301884002675 · Twitter Post
- https://twitter.com/transilienceai/status/1869250293512225254 · Twitter Post