PT-2024-21036 · Liferay · Liferay Portal+1

Published

2024-02-20

·

Updated

2024-12-11

·

CVE-2024-25607

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.2.0 through 7.4.3.15 Liferay DXP 7.4 before update 16 Liferay DXP 7.3 before update 4 Liferay DXP 7.2 before fix pack 17
Description The default password hashing algorithm (PBKDF2-HMAC-SHA1) in the affected software defaults to a low work factor, which allows attackers to quickly crack password hashes. This issue affects both Liferay Portal and Liferay DXP, with various versions being impacted.
Recommendations For Liferay Portal versions 7.2.0 through 7.4.3.15, update to a version with a higher work factor for the password hashing algorithm. For Liferay DXP 7.4, apply update 16 to address the issue. For Liferay DXP 7.3, apply update 4 to resolve the problem. For Liferay DXP 7.2, apply fix pack 17 to fix the vulnerability. As a temporary workaround, consider increasing the work factor for the PBKDF2-HMAC-SHA1 algorithm to make it more resistant to cracking.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-25607
GHSA-43H9-P3J4-39HM

Affected Products

Liferay Dxp
Liferay Portal