Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows a pre-authentication blind SSRF vulnerability in the portal-settings-authentication-opensso-web due to improper validation of user-supplied URLs. An attacker can exploit this issue to force the server to make arbitrary HTTP requests to internal systems, potentially leading to internal network enumeration or further exploitation.
References
| Link | Resource |
|---|---|
| https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-4581 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
16 Dec 2025, 16:43
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-4581 - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.6 |
| CPE | cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:*:*:*:*:*:*:* cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:* |
|
| First Time |
Liferay
Liferay liferay Portal Liferay digital Experience Platform |
11 Aug 2025, 18:32
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
09 Aug 2025, 05:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-08-09 05:15
Updated : 2025-12-16 16:43
NVD link : CVE-2025-4581
Mitre link : CVE-2025-4581
CVE.ORG link : CVE-2025-4581
JSON object : View
Products Affected
liferay
- digital_experience_platform
- liferay_portal
CWE
CWE-918
Server-Side Request Forgery (SSRF)
