CRITICAL🇵🇱 Wersja polska

CVE-2024-38002

CVSS 9.0v3.1pub. 2024-10-22upd. 2025-09-10

The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions before updating a workflow definition, which allows remote authenticated users to modify workflow definitions and execute arbitrary code (RCE) via the headless API.

🤖 AI Analysis
How it works

The vulnerability results from improper permission verification (CWE-862, CWE-863) in the workflow component. An authenticated user with basic access can send a request to the headless API to update workflow definitions without having the required permissions. By substituting a malicious workflow definition, it is possible to trigger arbitrary code execution on the server side.

Impact

An attacker can modify workflow definitions and execute arbitrary code on the server (RCE), which consequently may lead to complete system takeover, data disclosure, or destruction.

Mitigation & patch

Apply patches available from the vendor according to references (https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-38002). Until updates are applied, it is recommended to restrict access to the headless API only for trusted and authorized users.

Who is affected

Liferay Portal 7.3.2 – 7.4.3.111; Liferay DXP 2023.Q4.0 – 2023.Q4.5, 2023.Q3.1 – 2023.Q3.8, 7.4 GA – update 92, 7.3 GA – update 36

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Liferay Digital Experience Platform

    APP
    Liferay
    7.37.42023.q3.1 – 2023.q3.9 (excl.)2023.q4.0 – 2023.q4.6 (excl.)
  • Liferay Portal

    APP
    Liferay
    7.3.2 – 7.3.77.4.0 – 7.4.3.112 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2020-7961CRITICAL9.8⚠ KEVPL ✓same product

RCE przez deserializację w Liferay Portal via JSONWS

CVE-2024-8980CRITICAL9.6PL ✓same product

Liferay Portal/DXP: CSRF w Script Console umożliwia wykonanie kodu Groovy

CVE-2023-42496CRITICAL9.6PL ✓same product

Reflected XSS w Liferay Portal i DXP na stronie przypisywania ról

CVE-2023-40191CRITICAL9.0PL ✓same product

Reflected XSS w ustawieniach kont Liferay Portal i DXP

CVE-2023-42498CRITICAL9.6PL ✓same product

Reflected XSS w ekranie Language Override w Liferay Portal i DXP