CVE-2024-26268: Medium severity Liferay Liferay Portal vulnerability
User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to determine if an account exist in the application by comparing the request's response time.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.4.13.u27 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.u8 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp20 - Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.27-ga27
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26268?
CVE-2024-26268 has been classified as a medium severity vulnerability.
How do I fix CVE-2024-26268?
To fix CVE-2024-26268, upgrade Liferay Portal to version 7.4.3.27 or later, or update Liferay DXP to the appropriate versions mentioned in the vulnerability description.
What affected versions are impacted by CVE-2024-26268?
CVE-2024-26268 affects Liferay Portal versions 7.2.0 through 7.4.3.26, and Liferay DXP versions prior to updates 27, 8, and 20 respectively.
What is a user enumeration vulnerability like CVE-2024-26268?
A user enumeration vulnerability allows attackers to determine the existence of user accounts in the application, potentially leading to targeted attacks.
Are older unsupported versions of Liferay also vulnerable to CVE-2024-26268?
Yes, older unsupported versions of Liferay are also vulnerable to CVE-2024-26268.