Vulnerabilities
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-10-22 | CVE-2024-26271 | Cross-Site Request Forgery (CSRF) vulnerability in Liferay Digital Experience Platform and Liferay Portal Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 update 75 through update 92 and 7.3 update 32 through update 36 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code in the scripting console, (4) and perform other administrative actions via the _com_liferay_my_account_web_portlet_MyAccountPortlet_backURL parameter. | 8.8 |
2024-10-22 | CVE-2024-26272 | Cross-Site Request Forgery (CSRF) vulnerability in Liferay Digital Experience Platform and Liferay Portal Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 GA through update 35 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code in the scripting console, (4) and perform other administrative actions via the p_l_back_url parameter. | 8.8 |
2024-10-22 | CVE-2024-26273 | Cross-Site Request Forgery (CSRF) vulnerability in Liferay Digital Experience Platform and Liferay Portal Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 update 29 through update 35 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code in the scripting console, (4) and perform other administrative actions via the _com_liferay_commerce_catalog_web_internal_portlet_CommerceCatalogsPortlet_redirect parameter. | 8.8 |
2024-10-22 | CVE-2024-38002 | Incorrect Authorization vulnerability in Liferay Digital Experience Platform and Liferay Portal The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions before updating a workflow definition, which allows remote authenticated users to modify workflow definitions and execute arbitrary code (RCE) via the headless API. | 8.8 |
2024-10-22 | CVE-2024-43173 | Unspecified vulnerability in IBM Concert 1.0.0/1.0.1 IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute. | 3.7 |
2024-10-22 | CVE-2024-43177 | Improper Certificate Validation vulnerability in IBM Concert 1.0.0/1.0.1 IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute. | 9.8 |
2024-10-22 | CVE-2024-8980 | Cross-Site Request Forgery (CSRF) vulnerability in Liferay Digital Experience Platform and Liferay Portal The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA through fix pack 28, 7.0 GA through fix pack 102 and 6.2 GA through fix pack 173 does not sufficiently protect against Cross-Site Request Forgery (CSRF) attacks, which allows remote attackers to execute arbitrary Groovy script via a crafted URL or a XSS vulnerability. | 6.1 |
2024-10-22 | CVE-2024-10234 | Cross-site Scripting vulnerability in Redhat products A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. | 7.3 |
2024-10-22 | CVE-2024-50311 | Allocation of Resources Without Limits or Throttling vulnerability in Redhat Openshift Container Platform 4.0 A denial of service (DoS) vulnerability was found in OpenShift. | 6.5 |
2024-10-22 | CVE-2024-50312 | Unspecified vulnerability in Redhat Openshift Container Platform 4.0 A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. | 5.3 |