QID 731189
Date Published: 2024-02-22
QID 731189: Liferay Portal Hypertext Transfer Protocol (HTTP) Header Multiple Vulnerabilities (CVE-2024-26267)
Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.
CVE-2024-26267: In Liferay Portal and Liferay DXP the default value of the portal property http.header.version.verbosity is set to full, which allows remote attackers to easily identify the version of the application that is running and the vulnerabilities that affect that version via Liferay-Portal response header.
Affected Versions:
Liferay Portal from version 7.4.0 to 7.4.3.25.
Liferay Portal from version 7.3.0 to 7.3.7.
Liferay Portal 7.2.0 and 7.2.1.
Liferay Portal, older unsupported versions.
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Liferay Portal in the response banner.
Successful exploitation of this vulnerability allows remote attackers to affect confidentiality of the product.
The vendor has advised the following workarounds:
Set the following in portal(-ext).properties: http.header.version.verbosity=partial
CVEs related to QID 731189
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2024-26267 |
|