CVE-2024-25148: Infoleak
In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions the doAsUserId URL parameter may get leaked when creating linked content using the WYSIWYG editor and while impersonating a user. This may allow remote authenticated users to impersonate a user after accessing the linked content.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.u4 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp15 - Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25148?
CVE-2024-25148 is considered a moderate severity vulnerability due to the potential exposure of sensitive user information.
How do I fix CVE-2024-25148?
To fix CVE-2024-25148, update your Liferay installation to the patched versions: 7.3.10.u4, 7.2.10.fp15, or 7.4.2.
What versions are affected by CVE-2024-25148?
CVE-2024-25148 affects Liferay Portal versions 7.2.0 through 7.4.1, along with various unsupported older versions and specific versions of Liferay DXP.
What is the impact of CVE-2024-25148?
The impact of CVE-2024-25148 involves potential leakage of the `doAsUserId` URL parameter during content creation when impersonating a user.
Is CVE-2024-25148 limited to Liferay DXP?
No, CVE-2024-25148 also affects the Liferay Portal alongside certain versions of Liferay DXP.