Overview
Liferay Portal fails to properly protect against Cross-Site Request Forgery (CSRF). This may allow a remote attacker to be able to forge requests that Liferay Portal takes action upon.
Description
Liferay Portal is an enterprise portal solution that uses Java technologies. Liferay Portal fails to properly protect against CSRF attacks. |
Impact
A remote attacker may be able to forge requests that the Liferay Portal takes action upon. |
Solution
This issue is addressed in Liferay version 4.4.0, as specified in Liferay support document LEP-4739. Version 4.4.0 forces requests to be in POST format, which helps mitigate CSRF attacks. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Tomasz Kuczynski for reporting this vulnerability.
This document was written by Will Dormann.
Other Information
CVE IDs: | CVE-2008-0182 |
Severity Metric: | 4.39 |
Date Public: | 2008-01-10 |
Date First Published: | 2008-01-31 |
Date Last Updated: | 2008-01-31 20:20 UTC |
Document Revision: | 1 |