CVE-2025-62276: Medium severity Liferay Liferay Portal vulnerability
The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions uses an incorrect cache-control header, which allows local users to obtain access to downloaded files via the browser's cache.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62276?
CVE-2025-62276 is classified as a medium severity vulnerability due to improper cache-control header configurations.
How do I fix CVE-2025-62276?
To fix CVE-2025-62276, update your Liferay Portal or Liferay DXP to the latest patched version that addresses this issue.
Which versions are affected by CVE-2025-62276?
CVE-2025-62276 affects Liferay Portal versions from 7.4.0 to 7.4.3.111 and several versions of Liferay DXP, including 2023.Q4.0 to 2023.Q4.10 and 2023.Q3.1 to 2023.Q3.10.
What impact does CVE-2025-62276 have on Liferay applications?
The incorrect cache-control header in CVE-2025-62276 may lead to unintended caching of sensitive information, potentially exposing it to unauthorized users.
Is there a workaround for CVE-2025-62276 if immediate patching is not possible?
A recommended workaround for CVE-2025-62276 is to manually configure appropriate cache-control headers for affected modules until a full update can be applied.