CVE-2024-25146: Medium severity Liferay DXP vulnerability
Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exist or if the user does not have permission to access the site, which allows remote attackers to discover the existence of sites by enumerating URLs. This vulnerability occurs if locale.prepend.friendly.url.style=2 and if a custom 404 page is used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp18 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.u4 - Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.2 - Configuration
Change locale.prepend.friendly.url.style from 2 to a value other than 2 to avoid the vulnerability condition (it occurs if locale.prepend.friendly.url.style=2 and a custom 404 page is used).
Liferay Portal / Liferay DXP locale.prepend.friendly.url.style = 2
Event History
Frequently Asked Questions
What versions are affected by CVE-2024-25146?
CVE-2024-25146 affects Liferay Portal versions 7.2.0 through 7.4.1, and Liferay DXP 7.3 before service pack 3, along with older unsupported versions.
What is the severity of CVE-2024-25146?
The severity of CVE-2024-25146 has been classified as a moderate risk vulnerability.
How do I fix CVE-2024-25146?
To fix CVE-2024-25146, upgrade to Liferay Portal 7.4.2, Liferay DXP 7.3.10.u4, or Liferay DXP 7.2.10.fp18.
What type of vulnerability is CVE-2024-25146?
CVE-2024-25146 is a response manipulation vulnerability that alters the responses based on site access permissions.
Can I continue using my current version with CVE-2024-25146?
It is not recommended to continue using affected versions of Liferay due to the security risks posed by CVE-2024-25146.