CVE-2024-25607
published 2024-02-20CVE-2024-25607: The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.32%
24.8th percentile
The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions defaults to a low work factor, which allows attackers to quickly crack password hashes.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | digital_experience_platform | < 7.2 | 7.2 |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | dxp | 7.2.10 – 7.2.10-dxp-16 | — |
| liferay | dxp | 7.3.10 – 7.3.10-dxp-3 | — |
| liferay | dxp | 7.4.13 – 7.4.13.u15 | — |
| liferay | liferay_portal | <= 7.4.3.15 | — |
| liferay | portal | 7.2.0 – 7.4.3.15 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Liferay Portal defaults to a low work factor for the default password hashing algorithm
ghsa·2024-02-20
CVE-2024-25607 [HIGH] CWE-916 Liferay Portal defaults to a low work factor for the default password hashing algorithm
Liferay Portal defaults to a low work factor for the default password hashing algorithm
The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions defaults to a low work factor, which allows attackers to quickly crack password hashes.
OSV
Liferay Portal defaults to a low work factor for the default password hashing algorithm
osv·2024-02-20
CVE-2024-25607 [HIGH] Liferay Portal defaults to a low work factor for the default password hashing algorithm
Liferay Portal defaults to a low work factor for the default password hashing algorithm
The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions defaults to a low work factor, which allows attackers to quickly crack password hashes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-20
Published