CVE-2024-26270: Medium severity Liferay Portal vulnerability
The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 embeds the user’s hashed password in the page’s HTML source, which allows man-in-the-middle attackers to steal a user's hashed password.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 2023.Q3.5 - Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.100 - Upgrade
Upgrade
Liferay Portal 7.4to a version that resolves this vulnerability.Fixed in 7.4.3.99Patch patch 5 - Upgrade
Upgrade
Liferay DXP 2023.Q3to a version that resolves this vulnerability.Patch patch 5 - Upgrade
Upgrade
Liferay Portal 7.4 updateto a version that resolves this vulnerability.Fixed in 92
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26270?
CVE-2024-26270 is categorized as a medium severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2024-26270?
To remediate CVE-2024-26270, update Liferay Portal to version 7.4.3.100 or later and Liferay DXP to version 2023.Q3.5 or later.
What is the impact of CVE-2024-26270?
The impact of CVE-2024-26270 is that it allows attackers to steal a user's hashed password if they can intercept the web traffic.
Which Liferay versions are affected by CVE-2024-26270?
CVE-2024-26270 affects Liferay Portal versions 7.4.3.76 to 7.4.3.99 and Liferay DXP 2023.Q3 before patch 5.
Is CVE-2024-26270 a local or remote vulnerability?
CVE-2024-26270 is a remote vulnerability because it can be exploited over the network without physical access to the targeted system.