The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 13, and older unsupported versions, does not limit resource consumption when generating a preview image, which allows remote authenticated users to cause a denial of service (memory consumption) via crafted PNG images.
References
Link | Resource |
---|---|
https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25143 | Mitigation Vendor Advisory |
https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25143 | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-02-07 15:15
Updated : 2024-11-21 09:00
NVD link : CVE-2024-25143
Mitre link : CVE-2024-25143
CVE.ORG link : CVE-2024-25143
JSON object : View
Products Affected
liferay
- liferay_portal
- digital_experience_platform
CWE
CWE-770
Allocation of Resources Without Limits or Throttling