QID 731189

Date Published: 2024-02-22

QID 731189: Liferay Portal Hypertext Transfer Protocol (HTTP) Header Multiple Vulnerabilities (CVE-2024-26267)

Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.

CVE-2024-26267: In Liferay Portal and Liferay DXP the default value of the portal property http.header.version.verbosity is set to full, which allows remote attackers to easily identify the version of the application that is running and the vulnerabilities that affect that version via Liferay-Portal response header.

Affected Versions:
Liferay Portal from version 7.4.0 to 7.4.3.25.
Liferay Portal from version 7.3.0 to 7.3.7.
Liferay Portal 7.2.0 and 7.2.1.
Liferay Portal, older unsupported versions.

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Liferay Portal in the response banner.

Successful exploitation of this vulnerability allows remote attackers to affect confidentiality of the product.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Vendor has released patch. For more info, please refer to Liferay Portal Security Advisory CVE-2024-26267

    Workaround:
    The vendor has advised the following workarounds:
    Set the following in portal(-ext).properties: http.header.version.verbosity=partial

    CVEs related to QID 731189

    Software Advisories
    Advisory ID Software Component Link
    CVE-2024-26267 URL Logo liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-26267