CVE-2024-38002

Description

The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions before updating a workflow definition, which allows remote authenticated users to modify workflow definitions and execute arbitrary code (RCE) via the headless API.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
3.194

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2024-38002 are fixed in Liferay - release.dxp.bom 4.6Windows
Vulnerabilities CVE-2024-38002 are fixed in Liferay - release.dxp.bom 3.9Windows
Vulnerabilities CVE-2024-38002 are fixed in Liferay - release.dxp.bom 7.3.10Windows
Vulnerabilities CVE-2024-38002 are fixed in Liferay - release.dxp.bom 7.4.13Windows
Vulnerabilities CVE-2024-38002 are fixed in Liferay - release.portal.bom 7.4.3.112Windows
Vulnerabilities CVE-2024-38002 are fixed in Liferay - release.dxp.bom for Linux 4.6Linux
Vulnerabilities CVE-2024-38002 are fixed in Liferay - release.dxp.bom for Linux 3.9Linux
Vulnerabilities CVE-2024-38002 are fixed in Liferay - release.dxp.bom for Linux 7.3.10Linux
Vulnerabilities CVE-2024-38002 are fixed in Liferay - release.dxp.bom for Linux 7.4.13Linux
Vulnerabilities CVE-2024-38002 are fixed in Liferay - release.portal.bom for Linux 7.4.3.112Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234