Information disclosure in Liferay Enterprise Portal and Liferay DXP - CVE-2024-25146
Published: February 8, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected application returns with different responses depending on whether a site does not exist or if the user does not have permission to access the site. A remote attacker can discover the existence of sites by enumerating URLs.
Affected software
Liferay DXP
How to mitigate CVE-2024-25146
Liferay DXP - addressed in versions 7.2 fix pack 18, 7.3 service pack 3