The Remote App module in Liferay Portal through v7.4.3.8...
Moderate severity
Unreviewed
Published
Mar 4, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Mar 3, 2022
Published to the GitHub Advisory Database
Mar 4, 2022
Last updated
Feb 1, 2023
The Remote App module in Liferay Portal through v7.4.3.8 and Liferay DXP through v7.4 does not check if the origin of event messages it receives matches the origin of the Remote App, allowing attackers to exfiltrate the CSRF token via a crafted event message.
References