Summary
Liferay Portal/DXP contains an Insufficient Session Expiration issue where the Single Logout (SLO) API may fail to invalidate a user’s previous session. An attacker can reuse a stale session via the SLO endpoint to gain an authenticated context.
Affected Versions
The following platform versions are affected:
Liferay Portal: 7.3.3.131 through 7.4.3.121 Liferay DXP: 2024.Q4.0–2024.Q4.3 2024.Q3.1–2024.Q3.13 2024.Q2.0–2024.Q2.13 2024.Q1.1–2024.Q1.12
Remediation
Update to the fixed builds and, for Maven consumers of the SAML module, upgrade com.liferay:com.liferay.saml.impl to 5.0.51 or later. After upgrading, ensure session invalidation policies are enforced and verify SLO behavior end-to-end.