CVE-2024-25143: Medium severity Liferay Digital Experience Platform vulnerability
The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 13, and older unsupported versions, does not limit resource consumption when generating a preview image, which allows remote authenticated users to cause a denial of service (memory consumption) via crafted PNG images.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.3.7
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25143?
CVE-2024-25143 is considered a high-severity vulnerability due to its potential to allow remote authenticated attackers to cause resource exhaustion.
How do I fix CVE-2024-25143?
To fix CVE-2024-25143, upgrade Liferay Portal to version 7.3.7 or later, or apply the relevant patches for affected versions.
What software is affected by CVE-2024-25143?
CVE-2024-25143 affects Liferay Portal versions 7.2.0 through 7.3.6, and Liferay DXP 7.3 before service pack 3.
Can CVE-2024-25143 be exploited remotely?
Yes, CVE-2024-25143 can be exploited by remote authenticated attackers to affect resource consumption.
Are older versions of Liferay also affected by CVE-2024-25143?
Yes, older unsupported versions of Liferay Portal are also affected by CVE-2024-25143.