QID 731143
Date Published: 2024-02-12
QID 731143: Liferay Portal Denial of Service (DoS) Vulnerability (CVE-2024-25143)
Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.
CVE-2024-25143: The Document and Media widget In Liferay Portal does not limit resource consumption when generating a preview image, which allows remote authenticated users to cause a denial of service (memory consumption) via crafted PNG images.
Affected Versions:
Liferay Portal from version 7.3.0 to 7.3.6.
Liferay Portal from version 7.2.0 to 7.2.1.
Liferay Portal, older unsupported versions.
QID Detection Logic (Unauthenticated): This QID checks for vulnerable versions of Liferay Portal in the response banner.
Note: The QID is marked as potential as the workaround is present for this vulnerability and it is not possible to detect the applied workaround in an unauthenticated detection.
Successful exploitation of this vulnerability allows remote authenticated users to cause a denial of service (memory consumption) via crafted PNG images.
Remove "png" from the list of permitted extensions that can be uploaded to Document and Media.
CVEs related to QID 731143
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2024-25143 |
|