PT-2024-21033 · Liferay · Liferay Portal+1

Published

2024-02-20

·

Updated

2024-12-10

·

CVE-2024-25604

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.2.0 through 7.4.3.4 Liferay DXP versions 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17
Description The issue allows remote authenticated users with the VIEW user permission to edit their own permission via the "User and Organizations" section of the Control Panel, due to improper user permission checks.
Recommendations For Liferay Portal versions 7.2.0 through 7.4.3.4, update to a version that properly checks user permissions. For Liferay DXP version 7.4.13, apply service pack 3 or later. For Liferay DXP version 7.3, apply service pack 3 or later. For Liferay DXP version 7.2, apply fix pack 17 or later. As a temporary workaround, consider restricting access to the "User and Organizations" section of the Control Panel for users with the VIEW user permission.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-25604
GHSA-PW7P-3648-QQMG

Affected Products

Liferay Dxp
Liferay Portal