CVE-2024-38002

📊 9.0 CRITICAL0.9%🎯 0 exploits
📅 Published Oct 22, 2024
📋 Status: Modified

The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions before updating a workflow definition, which allows remote authenticated users to modify workflow definitions and execute arbitrary code (RCE) via the headless API.

🎯 Affected Products & Systems

135 product configurations affected

Filter by type:
Vulnerable
Version: ≥ 2023.q3.1 ∧ < 2023.q3.9
CPE:
cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*
Vulnerable
Version: ≥ 2023.q4.0 ∧ < 2023.q4.6
CPE:
cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:-:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:fix_pack_1:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:fix_pack_2:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:service_pack_1:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:service_pack_3:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update10:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update11:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update12:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update13:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update14:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update15:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update16:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update17:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update18:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update19:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update20:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update21:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update22:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update23:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update24:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update25:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update26:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update27:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update28:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update29:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update30:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update31:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update32:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update33:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update34:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update35:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update36:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update4:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update5:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update6:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update7:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update8:*:*:*:*:*:*
Vulnerable
Version: 7.3
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.3:update9:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:-:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update1:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update10:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update11:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update12:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update13:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update14:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update15:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update16:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update17:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update18:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update19:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update2:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update20:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update21:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update22:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update23:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update24:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update25:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update26:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update27:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update28:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update29:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update3:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update30:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update31:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update32:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update33:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update34:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update35:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update36:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update37:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update38:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update39:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update4:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update40:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update41:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update42:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update43:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update44:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update45:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update46:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update47:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update48:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update49:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update5:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update50:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update51:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update52:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update53:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update54:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update55:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update56:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update57:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update58:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update59:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update6:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update60:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update61:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update62:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update63:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update64:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update65:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update66:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update67:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update68:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update69:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update7:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update70:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update71:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update72:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update73:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update74:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update75:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update76:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update77:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update78:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update79:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update8:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update80:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update81:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update82:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update83:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update84:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update85:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update86:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update87:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update88:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update89:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update9:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update90:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update91:*:*:*:*:*:*
Vulnerable
Version: 7.4
CPE:
cpe:2.3:a:liferay:digital_experience_platform:7.4:update92:*:*:*:*:*:*
📱
Application
Vulnerable
Version: ≥ 7.3.2 ∧ ≤ 7.3.7
CPE:
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*
📱
Application
Vulnerable
Version: ≥ 7.4.0 ∧ < 7.4.3.112
CPE:
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*
135 productsscroll for more
Metrics
9.0 CRITICALCVSS v3.1[email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Attack Vector:
NETWORK
Complexity:
LOW
Privileges:
LOW
User Interaction:
REQUIRED
Confidentiality:
HIGH
Integrity:
HIGH
Availability:
HIGH
Scope:
CHANGED

🔍 Technical Details

Analysis Status
Modified
CVSS Details
9.0 (CRITICAL)v3.1
EPSS Details
0.9% (Minimal)75.1th percentile
Last updated: Nov 1, 2025
Exploitation probability within 30 days
Published Date
Oct 22, 2024 (1 year ago)
Last Modified
Sep 10, 2025 (1 month ago)
Security Weaknesses2
References2
CVE-2024-38002 - CRITICAL Severity Vulnerability | CoreDepth