First published: Thu Mar 20 2025(Updated: )
The data exposure vulnerability in Liferay Portal 7.4.0 through 7.4.3.126, and Liferay DXP 2024.Q3.0, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92 allows an unauthorized user to obtain entry data from forms.
Credit: security@liferay.com
Affected Software | Affected Version | How to fix |
---|---|---|
Liferay 7.4 GA | >=7.4.0<=7.4.3.126>=7.4<=7.4 GA | |
Liferay 7.4 GA | >=2024.Q2.0<=2024.Q2.12>=2024.Q1.1<=2024.Q1.12>=2023.Q4.0<=2023.Q4.10>=2023.Q3.1<=2023.Q3.10 | |
maven/com.liferay.portal:release.dxp.bom | >=2023.Q3.1<=2023.Q3.10 | |
maven/com.liferay.portal:release.dxp.bom | >=2023.Q4.0<=2023.Q4.10 | |
maven/com.liferay.portal:release.dxp.bom | >=2024.Q1.1<2024.Q1.13 | 2024.Q1.13 |
maven/com.liferay.portal:release.dxp.bom | >=2024.Q2.0<=2024.Q2.12 | |
maven/com.liferay.portal:release.dxp.bom | >=2024.Q3.0<2024.Q3.1 | 2024.Q3.1 |
maven/com.liferay.portal:release.portal.bom | >=7.4.0<7.4.3.129 | 7.4.3.129 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2565 is considered a data exposure vulnerability that allows unauthorized users to access sensitive entry data.
To fix CVE-2025-2565, update your Liferay Portal to version 7.4.3.127 or later, and Liferay DXP to the latest secure versions.
CVE-2025-2565 affects Liferay Portal versions 7.4.0 through 7.4.3.126 and specific versions of Liferay DXP from 2023.Q3.1 to 2024.Q2.12.
CVE-2025-2565 allows unauthorized access to entry data, which may include sensitive user input.
As of now, there is no public knowledge of active exploits for CVE-2025-2565, but it is recommended to apply the patch immediately.