CVE-2024-25606

Published Feb 20, 2024

Last updated 2 months ago

Overview

Description
XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before fix pack 20, and older unsupported versions allows attackers with permission to deploy widgets/portlets/extensions to obtain sensitive information or consume system resources via the Java2WsddTask._format method.
Source
security@liferay.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
8.7
Impact score
5.8
Exploitability score
2.3
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H
Severity
HIGH

Weaknesses

security@liferay.com
CWE-611
nvd@nist.gov
CWE-611

Social media

Hype score
Not currently trending

Configurations