CVE-2024-25144: Medium severity Liferay DXP vulnerability
The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6, 7.2 before fix pack 19, and older unsupported versions does not check the URL of the IFrame, which allows remote authenticated users to cause a denial-of-service (DoS) via a self referencing IFrame.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.4.13.u27 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.u6 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp19 - Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.27 - Upgrade
Upgrade
Liferay Portal IFrame widgetto a version that resolves this vulnerability.Fixed in 7.4.3.26 - Upgrade
Upgrade
Liferay Portalto a version that resolves this vulnerability.Fixed in 7.4 before update 27 - Upgrade
Upgrade
Liferay Portalto a version that resolves this vulnerability.Fixed in 7.3 before update 6 - Upgrade
Upgrade
Liferay Portalto a version that resolves this vulnerability.Fixed in 7.2 before fix pack 19
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25144?
CVE-2024-25144 has a critical severity due to the potential for authenticated users to exploit the vulnerability and cause denial of service.
How do I fix CVE-2024-25144?
To fix CVE-2024-25144, upgrade to Liferay DXP versions 7.4.13.u27, 7.3.10.u6, or 7.2.10.fp19, or the corresponding patched versions of Liferay Portal.
What versions of Liferay are affected by CVE-2024-25144?
CVE-2024-25144 affects Liferay Portal versions 7.2.0 through 7.4.3.26 and Liferay DXP versions 7.4 before update 27 and 7.3 before update 6.
Can anyone exploit CVE-2024-25144?
Yes, CVE-2024-25144 can be exploited by remote authenticated users due to insufficient URL validation in the IFrame widget.
What component is vulnerable in CVE-2024-25144?
CVE-2024-25144 affects the IFrame widget in Liferay Portal and DXP.