The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 13, and older unsupported versions, does not limit resource consumption when generating a preview image, which allows remote authenticated users to cause a denial of service (memory consumption) via crafted PNG images.
                
            References
                    | Link | Resource | 
|---|---|
| https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25143 | Mitigation Vendor Advisory | 
| https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25143 | Mitigation Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2024-02-07 15:15
Updated : 2024-11-21 09:00
NVD link : CVE-2024-25143
Mitre link : CVE-2024-25143
CVE.ORG link : CVE-2024-25143
JSON object : View
Products Affected
                liferay
- digital_experience_platform
- liferay_portal
CWE
                
                    
                        
                        CWE-770
                        
            Allocation of Resources Without Limits or Throttling
