CVE-2024-26265: Medium severity Liferay Liferay Portal vulnerability
The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions relies on a request parameter to limit the size of files that can be uploaded, which allows remote authenticated users to upload arbitrarily large files to the system's temp folder by modifying the maxFileSize parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.16 - Upgrade
Upgrade
Liferay Portal/Image Uploader moduleto a version that resolves this vulnerability.Fixed in 7.4.3.16 - Configuration
Do not rely on the client-supplied request parameter `maxFileSize` to enforce upload size limits; enforce server-side upload size constraints instead.
Liferay Portal/Liferay DXP - Image Uploader module maxFileSize (request parameter) = ignore/untrusted
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26265?
CVE-2024-26265 is rated as a high severity vulnerability due to its potential to allow arbitrary file uploads.
How do I fix CVE-2024-26265?
To fix CVE-2024-26265, update to Liferay Portal version 7.4.3.16 or later, or apply the recommended patches if you are using earlier versions.
What versions of Liferay are affected by CVE-2024-26265?
CVE-2024-26265 affects Liferay Portal versions 7.2.0 through 7.4.3.15, as well as older unsupported versions and specific Liferay DXP versions prior to update 16.
What is the nature of CVE-2024-26265?
CVE-2024-26265 is a vulnerability in the Image Uploader module that relies on a request parameter to limit file upload sizes, which can be manipulated.
Is there a workaround for CVE-2024-26265?
There is no known workaround for CVE-2024-26265 other than applying the necessary patches or upgrading the affected software.