In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack 19, and older unsupported versions the default value of the portal property `http.header.version.verbosity` is set to `full`, which allows remote attackers to easily identify the version of the application that is running and the vulnerabilities that affect that version via 'Liferay-Portal` response header.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Liferay

Published: 2024-02-20T13:01:23.251Z

Updated: 2024-06-04T17:49:00.661Z

Reserved: 2024-02-15T07:44:36.776Z


Link: CVE-2024-26267

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-02-20T13:15:08.843

Modified: 2024-02-20T19:50:53.960


Link: CVE-2024-26267

JSON object: View

cve-icon Redhat Information

No data.

CWE