The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions before updating a workflow definition, which allows remote authenticated users to modify workflow definitions and execute arbitrary code (RCE) via the headless API.
The vulnerability results from improper permission verification (CWE-862, CWE-863) in the workflow component. An authenticated user with basic access can send a request to the headless API to update workflow definitions without having the required permissions. By substituting a malicious workflow definition, it is possible to trigger arbitrary code execution on the server side.
An attacker can modify workflow definitions and execute arbitrary code on the server (RCE), which consequently may lead to complete system takeover, data disclosure, or destruction.
Apply patches available from the vendor according to references (https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-38002). Until updates are applied, it is recommended to restrict access to the headless API only for trusted and authorized users.
Liferay Portal 7.3.2 – 7.4.3.111; Liferay DXP 2023.Q4.0 – 2023.Q4.5, 2023.Q3.1 – 2023.Q3.8, 7.4 GA – update 92, 7.3 GA – update 36
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HLiferay Digital Experience Platform
APPLiferay7.37.42023.q3.1 – 2023.q3.9 (excl.)2023.q4.0 – 2023.q4.6 (excl.)Liferay Portal
APPLiferay7.3.2 – 7.3.77.4.0 – 7.4.3.112 (excl.)
Related vulnerabilities
RCE przez deserializację w Liferay Portal via JSONWS
Liferay Portal/DXP: CSRF w Script Console umożliwia wykonanie kodu Groovy
Reflected XSS w Liferay Portal i DXP na stronie przypisywania ról
Reflected XSS w ustawieniach kont Liferay Portal i DXP
Reflected XSS w ekranie Language Override w Liferay Portal i DXP