Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exist or if the user does not have permission to access the site, which allows remote attackers to discover the existence of sites by enumerating URLs. This vulnerability occurs if locale.prepend.friendly.url.style=2 and if a custom 404 page is used.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Liferay
Published: 2024-02-08T03:36:07.512Z
Updated: 2024-08-01T23:36:21.804Z
Reserved: 2024-02-06T10:32:42.567Z
Link: CVE-2024-25146
Vulnrichment
No data.
NVD
Status : Modified
Published: 2024-02-08T04:15:08.040
Modified: 2024-11-21T09:00:20.870
Link: CVE-2024-25146
Redhat
No data.