The Remote App module in Liferay Portal through v7.4.3.8 and Liferay DXP through v7.4 does not check if the origin of event messages it receives matches the origin of the Remote App, allowing attackers to exfiltrate the CSRF token via a crafted event message.
References
Link | Resource |
---|---|
http://liferay.com | Vendor Advisory |
https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-25146-csrf-token-exfiltration-via-remote-apps | Vendor Advisory |
https://www.securitum.pl | Not Applicable Third Party Advisory |
http://liferay.com | Vendor Advisory |
https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-25146-csrf-token-exfiltration-via-remote-apps | Vendor Advisory |
https://www.securitum.pl | Not Applicable Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:51
Type | Values Removed | Values Added |
---|---|---|
References | () http://liferay.com - Vendor Advisory | |
References | () https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-25146-csrf-token-exfiltration-via-remote-apps - Vendor Advisory | |
References | () https://www.securitum.pl - Not Applicable, Third Party Advisory |
09 Mar 2022, 19:38
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.securitum.pl - Not Applicable, Third Party Advisory | |
References | (MISC) http://liferay.com - Vendor Advisory | |
References | (MISC) https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-25146-csrf-token-exfiltration-via-remote-apps - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 5.0
v3 : 5.3 |
CPE | cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:* cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:* |
|
CWE | CWE-346 |
03 Mar 2022, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-03-03 00:15
Updated : 2024-11-21 06:51
NVD link : CVE-2022-25146
Mitre link : CVE-2022-25146
CVE.ORG link : CVE-2022-25146
JSON object : View
Products Affected
liferay
- digital_experience_platform
- liferay_portal
CWE
CWE-346
Origin Validation Error