CVE-2024-25604: Medium severity Liferay Digital Experience Platform vulnerability
Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions does not properly check user permissions, which allows remote authenticated users with the VIEW user permission to edit their own permission via the User and Organizations section of the Control Panel.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp17 - Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.5-ga5
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25604?
CVE-2024-25604 is considered a critical vulnerability due to its potential impact on user permission management.
How do I fix CVE-2024-25604?
To fix CVE-2024-25604, upgrade to a patched version of Liferay Portal or Digital Experience Platform as specified in the vendor's advisory.
What versions are affected by CVE-2024-25604?
CVE-2024-25604 affects Liferay Portal versions 7.2.0 through 7.4.3.4 and Liferay DXP 7.4.13, among other older unsupported versions.
What type of vulnerability is CVE-2024-25604?
CVE-2024-25604 is a security vulnerability that involves improper user permission checks.
Can CVE-2024-25604 allow unauthorized actions?
Yes, CVE-2024-25604 allows remote authenticated users with VIEW permission to edit content, which could lead to unauthorized changes.