CVE-2024-25607

HIGH

Liferay Portal/DXP - Info Disclosure

Title source: llm
STIX 2.1

Description

The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions defaults to a low work factor, which allows attackers to quickly crack password hashes.

Scores

CVSS v3 8.1
EPSS 0.0010
EPSS Percentile 27.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-916
Status published
Products (8)
com.liferay.portal/com.liferay.portal.kernel 0 - 38.0.0Maven
com.liferay.portal/release.dxp.bom 7.3.0 - 7.3.10.u4Maven
com.liferay.portal/release.portal.bom 0 - 7.4.3.14Maven
liferay/digital_experience_platform 7.2 (23 CPE variants)
liferay/digital_experience_platform 7.3 (5 CPE variants)
liferay/digital_experience_platform 7.4 (16 CPE variants)
liferay/digital_experience_platform < 7.2
liferay/liferay_portal < 7.4.3.15
Published Feb 20, 2024
Tracked Since Feb 18, 2026