QID 731180

Date Published: 2024-02-22

QID 731180: Liferay Portal External Entity Injection (XXE) Vulnerability (CVE-2024-25606)

Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.

CVE-2024-25606: XXE vulnerability in Liferay Portal allows attackers with permission to deploy widgets/portlets/extensions to obtain sensitive information or consume system resources via the Java2WsddTask._format method.

Affected Versions:
Liferay Portal from version 7.4.0 to 7.4.3.7.
Liferay Portal from version 7.3.0 to 7.3.7.
Liferay Portal 7.2.0 and 7.2.1.
Liferay Portal, older unsupported versions.

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Liferay Portal in the response banner.

Successful exploitation of this vulnerability attackers with permission to deploy widgets/portlets/extensions to obtain sensitive information.

  • CVSS V3 rated as High - 8 severity.
  • CVSS V2 rated as Low - 0 severity.
  • Solution
    Vendor has released patch. For more info, please refer to Liferay Portal Security Advisory

    CVEs related to QID 731180

    Software Advisories
    Advisory ID Software Component Link
    Liferay Portal URL Logo liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-25606