2024-10-22 16:03:54 +00:00
{
"id" : "CVE-2024-26271" ,
"sourceIdentifier" : "security@liferay.com" ,
"published" : "2024-10-22T15:15:05.523" ,
2024-12-10 23:03:51 +00:00
"lastModified" : "2024-12-10T21:07:04.467" ,
2024-10-30 17:03:21 +00:00
"vulnStatus" : "Analyzed" ,
2024-10-22 16:03:54 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 update 75 through update 92 and 7.3 update 32 through update 36 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code in the scripting console, (4) and perform other administrative actions via the _com_liferay_my_account_web_portlet_MyAccountPortlet_backURL parameter."
2024-10-23 16:03:56 +00:00
} ,
{
"lang" : "es" ,
"value" : "La vulnerabilidad de Cross-Site Request Forgery (CSRF) en el widget Mi cuenta en Liferay Portal 7.4.3.75 a 7.4.3.111, y Liferay DXP 2023.Q4.0 a 2023.Q4.2, 2023.Q3.1 a 2023.Q3.5, 7.4 actualizaci\u00f3n 75 a 92 y 7.3 actualizaci\u00f3n 32 a 36 permite a atacantes remotos (1) cambiar las contrase\u00f1as de los usuarios, (2) apagar el servidor, (3) ejecutar c\u00f3digo arbitrario en la consola de scripts, (4) y realizar otras acciones administrativas a trav\u00e9s del par\u00e1metro _com_liferay_my_account_web_portlet_MyAccountPortlet_backURL."
2024-10-22 16:03:54 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2024-10-30 17:03:21 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "security@liferay.com" ,
"type" : "Secondary" ,
2024-10-30 17:03:21 +00:00
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 8.8 ,
"baseSeverity" : "HIGH" ,
2024-10-30 17:03:21 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2024-10-30 17:03:21 +00:00
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 5.9
} ,
2024-10-22 16:03:54 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2024-10-22 16:03:54 +00:00
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 8.8 ,
"baseSeverity" : "HIGH" ,
2024-10-22 16:03:54 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2024-10-22 16:03:54 +00:00
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
2024-10-30 17:03:21 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "security@liferay.com" ,
"type" : "Secondary" ,
2024-10-30 17:03:21 +00:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-352"
}
]
} ,
2024-10-22 16:03:54 +00:00
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2024-10-22 16:03:54 +00:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-352"
}
]
}
] ,
2024-10-30 17:03:21 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
2024-12-10 23:03:51 +00:00
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "2023.q3.1" ,
"versionEndExcluding" : "2023.q3.6" ,
"matchCriteriaId" : "935D404E-76A6-4405-8A74-0E70E50C3FCC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "2023.q4.0" ,
"versionEndExcluding" : "2023.q4.3" ,
"matchCriteriaId" : "3758E9CF-12EC-4025-85BB-1D5EEA99359A"
} ,
2024-10-30 17:03:21 +00:00
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.3:update32:*:*:*:*:*:*" ,
"matchCriteriaId" : "660F37C6-61E6-4C34-8A7E-99C7DBEB8319"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.3:update33:*:*:*:*:*:*" ,
"matchCriteriaId" : "5AD8D0D3-31AC-41E5-A780-5D5B18BF6991"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.3:update34:*:*:*:*:*:*" ,
"matchCriteriaId" : "02D4C998-77F5-4428-A7B9-F7D909E23E92"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.3:update35:*:*:*:*:*:*" ,
"matchCriteriaId" : "C6984AC8-461D-488F-A911-7BF1D12B44A5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.4:update75:*:*:*:*:*:*" ,
"matchCriteriaId" : "BB5558B0-6714-4B3A-B287-1943517A975A"
} ,
2024-12-10 23:03:51 +00:00
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.4:update76:*:*:*:*:*:*" ,
"matchCriteriaId" : "7E325115-EEBC-41F4-8606-45270DA40B98"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.4:update77:*:*:*:*:*:*" ,
"matchCriteriaId" : "848B2C72-447D-46E2-A5A7-43CF3764E578"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.4:update78:*:*:*:*:*:*" ,
"matchCriteriaId" : "26A0AF15-52A9-46FD-8157-359141332EAF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.4:update79:*:*:*:*:*:*" ,
"matchCriteriaId" : "63D63872-C1D0-444F-BCC7-A514F323C256"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.4:update80:*:*:*:*:*:*" ,
"matchCriteriaId" : "9D9FA9AD-39D3-412A-B794-E1B29EEEEC4A"
} ,
2024-10-30 17:03:21 +00:00
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.4:update81:*:*:*:*:*:*" ,
"matchCriteriaId" : "294D8A56-A797-433C-A06E-106B2179151A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.4:update82:*:*:*:*:*:*" ,
"matchCriteriaId" : "824D88D9-4645-4CAD-8CAB-30F27DD388C4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.4:update83:*:*:*:*:*:*" ,
"matchCriteriaId" : "F6E8C952-B455-46E4-AC3D-D38CAF189F60"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.4:update84:*:*:*:*:*:*" ,
"matchCriteriaId" : "CD77C0EE-AC79-4443-A502-C1E02F806911"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.4:update85:*:*:*:*:*:*" ,
"matchCriteriaId" : "648EB53C-7A90-4DA6-BF1C-B5336CDE30C7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.4:update86:*:*:*:*:*:*" ,
"matchCriteriaId" : "39835EF7-8E93-4695-973D-6E9B76C67372"
} ,
{
"vulnerable" : true ,
2024-12-10 23:03:51 +00:00
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.4:update87:*:*:*:*:*:*" ,
"matchCriteriaId" : "2A05FB86-332B-44E3-93CB-82465A38976E"
2024-10-30 17:03:21 +00:00
} ,
{
"vulnerable" : true ,
2024-12-10 23:03:51 +00:00
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.4:update88:*:*:*:*:*:*" ,
"matchCriteriaId" : "7C754823-899C-4EEF-ACB7-E1551FA88B25"
2024-10-30 17:03:21 +00:00
} ,
{
"vulnerable" : true ,
2024-12-10 23:03:51 +00:00
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.4:update89:*:*:*:*:*:*" ,
"matchCriteriaId" : "493D4C18-DEE2-4040-9C13-3A9AB2CE47BF"
2024-10-30 17:03:21 +00:00
} ,
{
"vulnerable" : true ,
2024-12-10 23:03:51 +00:00
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.4:update90:*:*:*:*:*:*" ,
"matchCriteriaId" : "8F17DD75-E63B-4E4C-B136-D43F17B389EF"
2024-10-30 17:03:21 +00:00
} ,
{
"vulnerable" : true ,
2024-12-10 23:03:51 +00:00
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.4:update91:*:*:*:*:*:*" ,
"matchCriteriaId" : "62EE759A-78AD-40D6-8C5B-10403A8A4A89"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:digital_experience_platform:7.4:update92:*:*:*:*:*:*" ,
"matchCriteriaId" : "865ABA1F-CA99-4602-B325-F81C9778855C"
2024-10-30 17:03:21 +00:00
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "7.4.3.75" ,
"versionEndExcluding" : "7.4.3.112" ,
"matchCriteriaId" : "FEDE37FB-83BC-41D6-94D7-DE087BC4FE14"
}
]
}
]
}
] ,
2024-10-22 16:03:54 +00:00
"references" : [
{
"url" : "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-26271" ,
2024-10-30 17:03:21 +00:00
"source" : "security@liferay.com" ,
"tags" : [
"Vendor Advisory"
]
2024-10-22 16:03:54 +00:00
}
]
}