PT-2024-21034 · Liferay · Liferay Portal+1

Published

2024-02-20

·

Updated

2024-12-10

·

CVE-2024-25605

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.2.0 through 7.4.3.4 Liferay DXP versions 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17
Description The Journal module in Liferay Portal grants guest users view permission to web content templates by default. This allows remote attackers to view any template via the UI or API.
Recommendations For Liferay Portal versions 7.2.0 through 7.4.3.4, update to a version that includes the fix for this issue. For Liferay DXP version 7.4.13, apply service pack 3 or later. For Liferay DXP version 7.3, apply service pack 3 or later. For Liferay DXP version 7.2, apply fix pack 17 or later. As a temporary workaround, consider restricting guest user permissions to web content templates until a patch is available.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-25605
GHSA-MF8H-GRFG-J9J3

Affected Products

Liferay Dxp
Liferay Portal