Issue
- CVE-2024-38819: Path traversal vulnerability in functional web frameworks (2nd report) is related to the usage of WebMvc.jar. Is Liferay vulnerable to this vulnerability?
Environment
- Liferay DXP 7.3 +
Resolution
-
A fix was made available in version 5.3.41. However spring only gives the updated version for the commercial customer. In our 7.3.x upstream and beyond, we removed the usage of spring-webmvc as it is unused to avoid this issue.
In case you are using an older version, please open a ticket requesting a hotfix from Liferay Support in order to remove the spring jars files.