CVE-2024-25608: Medium severity Liferay Digital Experience Platform vulnerability
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by using the 'REPLACEMENT CHARACTER' (U+FFFD), which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect parameter (2) FORWARDURL parameter, (3) noSuchEntryRedirect parameter, and (4) others parameters that rely on HtmlUtil.escapeRedirect.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.4.13.u19 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.u4 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp19 - Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.19-ga19
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25608?
The severity of CVE-2024-25608 is high due to its potential for remote exploitation.
How do I fix CVE-2024-25608?
To fix CVE-2024-25608, update to Liferay Portal 7.4.3.19 or later, or apply the appropriate patches in affected versions.
Which versions are affected by CVE-2024-25608?
CVE-2024-25608 affects Liferay Portal versions 7.2.0 through 7.4.3.18 and older unsupported versions.
What kind of vulnerability is CVE-2024-25608?
CVE-2024-25608 is a security vulnerability in the HtmlUtil.escapeRedirect function that can be circumvented.
Can CVE-2024-25608 be exploited remotely?
Yes, CVE-2024-25608 can be exploited remotely due to the circumvention of input validation.