The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 does not check if the origin of event messages it receives matches the origin of the Remote App, allowing attackers to exfiltrate the CSRF token via a crafted event message.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.liferay:com.liferay.remote.app.web(Maven) | 0 | 2.0.21 | N/A |
| com.liferay.portal:release.dxp.bom(Maven) | 0 | 7.4.13.u5 | N/A |
CVSS Metrics