Headline
GHSA-6v93-frf9-2rp8: Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, and 7.4 GA through update 92 allow a pre-authentication blind SSRF vulnerability in the portal-settings-authentication-opensso-web component due to improper validation of user-supplied URLs. An attacker can exploit this issue to force the server to make arbitrary HTTP requests to internal systems, potentially leading to internal network enumeration or further exploitation.
- GitHub Advisory Database
- GitHub Reviewed
- CVE-2025-4581
Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
Moderate severity GitHub Reviewed Published Aug 9, 2025 to the GitHub Advisory Database • Updated Aug 11, 2025
Package
maven com.liferay.portal:release.dxp.bom (Maven)
Affected versions
>= 2025.Q1.0, <= 2025.Q1.4
>= 2024.Q4.0, <= 2024.Q4.7
>= 2024.Q3.1, <= 2024.Q3.13
>= 2024.Q2.0, <= 2024.Q2.13
>= 2024.Q1.0, <= 2024.Q1.15
<= 7.4.13.u92
Patched versions
2025.Q1.5
2024.Q1.16
maven com.liferay.portal:release.portal.bom (Maven)
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, and 7.4 GA through update 92 allow a pre-authentication blind SSRF vulnerability in the portal-settings-authentication-opensso-web component due to improper validation of user-supplied URLs. An attacker can exploit this issue to force the server to make arbitrary HTTP requests to internal systems, potentially leading to internal network enumeration or further exploitation.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-4581
- https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-4581
Published to the GitHub Advisory Database
Aug 9, 2025
Last updated
Aug 11, 2025