PT-2024-27874 · Liferay · Liferay Portal+1
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Liferay Portal versions 7.3.2 through 7.4.3.111
Liferay DXP versions 2023.Q4.0 through 2023.Q4.5
Liferay DXP versions 2023.Q3.1 through 2023.Q3.8
Liferay DXP 7.4 GA through update 92
Liferay DXP 7.3 GA through update 36
Description
The workflow component does not properly check user permissions before updating a workflow definition, allowing remote authenticated users to modify workflow definitions and execute arbitrary code via the headless API.
Recommendations
For Liferay Portal versions 7.3.2 through 7.4.3.111, update to a version that includes the fix for this issue.
For Liferay DXP versions 2023.Q4.0 through 2023.Q4.5, update to a version that includes the fix for this issue.
For Liferay DXP versions 2023.Q3.1 through 2023.Q3.8, update to a version that includes the fix for this issue.
For Liferay DXP 7.4 GA through update 92, update to a version that includes the fix for this issue.
For Liferay DXP 7.3 GA through update 36, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the headless API to minimize the risk of exploitation.
Fix
RCE
Incorrect Authorization
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Liferay Dxp
Liferay Portal