CVE-2024-25605

The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions grants guest users view permission to web content templates by default, which allows remote attackers to view any template via the UI or API.
Configurations

No configuration.

History

20 Feb 2024, 19:50

Type Values Removed Values Added
Summary
  • (es) El módulo Journal en Liferay Portal 7.2.0 a 7.4.3.4 y versiones anteriores no compatibles, y Liferay DXP 7.4.13, 7.3 anteriores al service pack 3, 7.2 anteriores al fix pack 17 y versiones anteriores no compatibles otorga a los usuarios invitados permiso de visualización del contenido web plantillas de forma predeterminada, lo que permite a atacantes remotos ver cualquier plantilla a través de la interfaz de usuario o API.

20 Feb 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-20 09:15

Updated : 2024-02-20 19:50


NVD link : CVE-2024-25605

Mitre link : CVE-2024-25605

CVE.ORG link : CVE-2024-25605


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions