We found results for “”
CVE-2024-38002
Good to know:
Date: October 22, 2024
The workflow component in Liferay Portal and Liferay DXP does not properly check user permissions before updating a workflow definition, which allows remote authenticated users to modify workflow definitions and execute arbitrary code (RCE) via the headless API.
Severity Score
Severity Score
Top Fix
Upgrade Version
Upgrade to version com.liferay.portal:release.portal.bom:7.4.3.112-ga112;com.liferay.portal:release.dxp.bom:7.3.10.u36;com.liferay.portal:release.dxp.bom:7.4.13.u92
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | REQUIRED |
| Scope (S): | CHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


