CVE-2024-25608
published 2024-02-20CVE-2024-25608: HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4…
PriorityP178medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
0.96%
57.9th percentile
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by using the 'REPLACEMENT CHARACTER' (U+FFFD), which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, (3) `noSuchEntryRedirect` parameter, and (4) others parameters that rely on HtmlUtil.escapeRedirect.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | digital_experience_platform | < 7.2 | 7.2 |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | dxp | 7.2.10 – 7.2.10-dxp-18 | — |
| liferay | dxp | 7.3.10 – 7.3.10-dxp-3 | — |
| liferay | dxp | 7.4.13 – 7.4.13.u18 | — |
| liferay | liferay_portal | < 7.4.3.19 | 7.4.3.19 |
| liferay | portal | 7.2.0 – 7.4.3.18 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Look for HTTP 302 redirects from Liferay Portal where the Location header contains the pattern 'http://oast.me?@localhost' or similar external URLs — indicating successful bypass of HtmlUtil.escapeRedirect via the U+FFFD replacement character. ↗
- →Monitor GET requests to /html/common/forward_jsp.jsp with a FORWARD_URL parameter containing the UTF-8 encoded replacement character (%EF%BF%BD / U+FFFD) to detect open redirect exploitation attempts. ↗
- →Use Shodan/FOFA to identify exposed Liferay instances via favicon hash 129457226 as potential targets for this CVE. ↗
- ·Multiple parameters are affected beyond FORWARD_URL, including 'redirect', 'noSuchEntryRedirect', and any other parameter that internally calls HtmlUtil.escapeRedirect — detection rules should cover all such parameters. ↗
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
vulncheck6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Replacement Character
osv·2024-02-20
CVE-2024-25608 [MEDIUM] Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Replacement Character
Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Replacement Character
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by using the 'REPLACEMENT CHARACTER' (U+FFFD), which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, (3) `noSuchEntryRedirect` parameter, and (4) others parameters that rely on HtmlUtil.escapeRedirect.
GHSA
Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Replacement Character
ghsa·2024-02-20
CVE-2024-25608 [MEDIUM] CWE-601 Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Replacement Character
Liferay Portal and Liferay DXP's HtmlUtil.escapeRedirect Can Be Circumvented via Replacement Character
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by using the 'REPLACEMENT CHARACTER' (U+FFFD), which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, (3) `noSuchEntryRedirect` parameter, and (4) others parameters that rely on HtmlUtil.escapeRedirect.
VulnCheck
liferay digital_experience_platform URL Redirection to Untrusted Site ('Open Redirect')
vulncheck·2024·CVSS 6.1
CVE-2024-25608 [MEDIUM] liferay digital_experience_platform URL Redirection to Untrusted Site ('Open Redirect')
liferay digital_experience_platform URL Redirection to Untrusted Site ('Open Redirect')
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by using the 'REPLACEMENT CHARACTER' (U+FFFD), which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, (3) `noSuchEntryRedirect` parameter, and (4) others parameters that rely on HtmlUtil.escapeRedirect.
Affected: liferay digital_experience_platform
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are una
No detection rules found.
Nuclei
Liferay Portal - Open Redirect
nuclei·CVSS 6.1
CVE-2024-25608 [MEDIUM] Liferay Portal - Open Redirect
Liferay Portal - Open Redirect
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by using the 'REPLACEMENT CHARACTER' (U+FFFD), which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, (3) `noSuchEntryRedirect` parameter, and (4) others parameters that rely on HtmlUtil.escapeRedirect.
Template:
id: CVE-2024-25608
info:
name: Liferay Portal - Open Redirect
author: daffainfo
severity: medium
description: |
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before u
No writeups or analysis indexed.
2024-02-20
Published
Exploited in the wild