CVE-2024-26267: Medium severity Liferay portal vulnerability
In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack 19, and older unsupported versions the default value of the portal property http.header.version.verbosity is set to full, which allows remote attackers to easily identify the version of the application that is running and the vulnerabilities that affect that version via 'Liferay-Portal response header.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.4.13.u26 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.u5 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp19 - Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.26-ga26 - Configuration
For Liferay Portal versions 7.2.0 through 7.4.3.25 and older unsupported versions, and for Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack 19, change the portal property `http.header.version.verbosity` from `full` to a non-`full` value to prevent version disclosure via the `Liferay-Portal` response header.
Liferay Portal http.header.version.verbosity = default (not full)
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26267?
The severity of CVE-2024-26267 has not been explicitly rated, but it represents a significant risk due to the exposure of sensitive information.
How do I fix CVE-2024-26267?
To fix CVE-2024-26267, update Liferay Portal to version 7.4.3.26 or later, or apply the necessary updates for Liferay DXP as specified by the vendor.
What versions are affected by CVE-2024-26267?
CVE-2024-26267 affects Liferay Portal versions 7.2.0 through 7.4.3.25 and older unsupported versions, as well as Liferay DXP 7.4 before update 26.
What is the impact of CVE-2024-26267?
The impact of CVE-2024-26267 is that it potentially allows remote attackers to access sensitive version information through exposed HTTP headers.
Is there a workaround for CVE-2024-26267 if I cannot update immediately?
As a temporary workaround for CVE-2024-26267, consider configuring the portal property 'http.header.version.verbosity' to a less verbose setting until an update can be applied.