We found results for “”
CVE-2024-26267
Good to know:
Date: February 20, 2024
In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack 19, and older unsupported versions the default value of the portal property "http.header.version.verbosity" is set to "full", which allows remote attackers to easily identify the version of the application that is running and the vulnerabilities that affect that version via 'Liferay-Portal` response header.
Language: Java
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Initialization of a Resource with an Insecure Default
CWE-1188Top Fix
Upgrade Version
Upgrade to version com.liferay.portal:release.dxp.bom:7.2.10.fp19;com.liferay.portal:release.dxp.bom:7.3.10.u5;com.liferay.portal:release.dxp.bom:7.4.13.u26
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


