5.3

CVE-2024-25605

The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions grants guest users view permission to web content templates by default, which allows remote attackers to view any template via the UI or API.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Liferay ≫ Digital Experience Platform Version 7.2 Update -
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_1
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_10
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_11
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_12
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_13
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_14
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_15
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_16
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_2
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_3
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_4
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_5
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_6
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_7
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_8
Liferay ≫ Digital Experience Platform Version 7.2 Update fix_pack_9
Liferay ≫ Digital Experience Platform Version 7.2 Update service_pack_1
Liferay ≫ Digital Experience Platform Version 7.2 Update service_pack_2
Liferay ≫ Digital Experience Platform Version 7.2 Update service_pack_3
Liferay ≫ Digital Experience Platform Version 7.2 Update service_pack_4
Liferay ≫ Digital Experience Platform Version 7.2 Update service_pack_5
Liferay ≫ Digital Experience Platform Version 7.3 Update -
Liferay ≫ Digital Experience Platform Version 7.3 Update fix_pack_1
Liferay ≫ Digital Experience Platform Version 7.3 Update fix_pack_2
Liferay ≫ Digital Experience Platform Version 7.3 Update service_pack_1
Liferay ≫ Digital Experience Platform Version 7.4 Update -
Liferay ≫ Liferay Portal Version < 7.4.3.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.48% 0.376
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
security@liferay.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25605
Vendor Advisory