QID 731177
Date Published: 2024-02-26
QID 731177: Liferay Portal Multiple Vulnerabilities
Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.
Affected Versions:
Liferay Portal from version 7.4.0 to 7.4.2
Liferay Portal from version 7.3.0 to 7.3.7.
Liferay Portal 7.2.0 and 7.2.1.
Liferay Portal, older unsupported versions.
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Liferay Portal in the response banner.
Successful exploitation of this vulnerability allows remote authenticated users to obtain a user's full name from the page's title by enumerating user screen names.
Solution
Vendor has released patch. For more info, please refer to Liferay Portal Security Advisory
Vendor References
- Liferay Portal(CVE-2024-25150) -
liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-25150 - Liferay Portal(CVE-2024-25152) -
liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-25152 - Liferay Portal(CVE-2024-25601) -
liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-25601 - Liferay Portal(CVE-2024-25602) -
liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-25602
CVEs related to QID 731177
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Liferay Portal Security Advisory |
|