CVE-2024-26267Initialization of a Resource with an Insecure Default in Digital Experience Platform

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 54.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20

Description

In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack 19, and older unsupported versions the default value of the portal property `http.header.version.verbosity` is set to `full`, which allows remote attackers to easily identify the version of the application that is running and the vulnerabilities that affect that version via 'Liferay-Portal` response header.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

NVDliferay/liferay_portal7.4.07.4.3.26+1
CVEListV5liferay/portal7.2.07.4.3.25
CVEListV5liferay/dxp7.4.137.4.13.u25+2

🔴Vulnerability Details

3
OSV
Liferay Portal and Liferay DXP HTTP Header Can Expose Versions2024-02-20
CVEList
CVE-2024-26267: In Liferay Portal 72024-02-20
GHSA
Liferay Portal and Liferay DXP HTTP Header Can Expose Versions2024-02-20
CVE-2024-26267 — MEDIUM severity | cvebase