The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions before updating a workflow definition, which allows remote authenticated users to modify workflow definitions and execute arbitrary code (RCE) via the headless API.
References
Link | Resource |
---|---|
https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-38002 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
30 Oct 2024, 14:47
Type | Values Removed | Values Added |
---|---|---|
References | () https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-38002 - Vendor Advisory | |
CPE | cpe:2.3:a:liferay:digital_experience_platform:2023:q4.5:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:-:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:2023:q4.0:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:2023:q3.8:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:-:*:*:*:*:*:* cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:2023:q3.1:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
First Time |
Liferay
Liferay liferay Portal Liferay digital Experience Platform |
23 Oct 2024, 15:12
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
22 Oct 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-22 15:15
Updated : 2024-10-30 14:47
NVD link : CVE-2024-38002
Mitre link : CVE-2024-38002
CVE.ORG link : CVE-2024-38002
JSON object : View
Products Affected
liferay
- liferay_portal
- digital_experience_platform
CWE
CWE-863
Incorrect Authorization