PT-2024-27874 · Liferay · Liferay Portal+1

·

CVE-2024-38002

·

Published

2024-10-22

·

Updated

2025-10-13

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.3.2 through 7.4.3.111 Liferay DXP versions 2023.Q4.0 through 2023.Q4.5 Liferay DXP versions 2023.Q3.1 through 2023.Q3.8 Liferay DXP 7.4 GA through update 92 Liferay DXP 7.3 GA through update 36
Description The workflow component does not properly check user permissions before updating a workflow definition, allowing remote authenticated users to modify workflow definitions and execute arbitrary code via the headless API.
Recommendations For Liferay Portal versions 7.3.2 through 7.4.3.111, update to a version that includes the fix for this issue. For Liferay DXP versions 2023.Q4.0 through 2023.Q4.5, update to a version that includes the fix for this issue. For Liferay DXP versions 2023.Q3.1 through 2023.Q3.8, update to a version that includes the fix for this issue. For Liferay DXP 7.4 GA through update 92, update to a version that includes the fix for this issue. For Liferay DXP 7.3 GA through update 36, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the headless API to minimize the risk of exploitation.

Fix

RCE

Incorrect Authorization

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-38002
GHSA-3MFQ-FP2F-VWQH

Affected Products

Liferay Dxp
Liferay Portal