The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions before updating a workflow definition, which allows remote authenticated users to modify workflow definitions and execute arbitrary code (RCE) via the headless API.
History

Wed, 30 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Liferay digital Experience Platform
Liferay liferay Portal
CPEs cpe:2.3:a:liferay:digital_experience_platform:2023:q3.1:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023:q3.8:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023:q4.0:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023:q4.5:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.3:-:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:-:*:*:*:*:*:*
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*
Vendors & Products Liferay digital Experience Platform
Liferay liferay Portal

Tue, 22 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Liferay
Liferay dxp
Liferay portal
CPEs cpe:2.3:a:liferay:dxp:*:*:*:*:*:*:*:*
cpe:2.3:a:liferay:portal:*:*:*:*:*:*:*:*
Vendors & Products Liferay
Liferay dxp
Liferay portal
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Description The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions before updating a workflow definition, which allows remote authenticated users to modify workflow definitions and execute arbitrary code (RCE) via the headless API.
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Liferay

Published: 2024-10-22T15:12:42.223Z

Updated: 2024-10-22T15:22:55.078Z

Reserved: 2024-06-11T15:40:10.985Z

Link: CVE-2024-38002

cve-icon Vulnrichment

Updated: 2024-10-22T15:22:45.625Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-22T15:15:06.277

Modified: 2024-10-30T14:47:10.953

Link: CVE-2024-38002

cve-icon Redhat

No data.