Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rpx3-f938-xj5q

Опубликовано: 24 сент. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

Liferay Portal and DXP does not properly expire sessions

Summary

Liferay Portal/DXP contains an Insufficient Session Expiration issue where the Single Logout (SLO) API may fail to invalidate a user’s previous session. An attacker can reuse a stale session via the SLO endpoint to gain an authenticated context.

Affected Versions

The following platform versions are affected:

  • Liferay Portal:
    • 7.3.3.131 through 7.4.3.121
  • Liferay DXP:
    • 2024.Q4.02024.Q4.3
    • 2024.Q3.12024.Q3.13
    • 2024.Q2.02024.Q2.13
    • 2024.Q1.12024.Q1.12

Remediation

Update to the fixed builds and, for Maven consumers of the SAML module, upgrade com.liferay:com.liferay.saml.impl to 5.0.51 or later. After upgrading, ensure session invalidation policies are enforced and verify SLO behavior end-to-end.

Пакеты

Наименование

com.liferay:com.liferay.saml.impl

maven
Затронутые версииВерсия исправления

< 5.0.51

5.0.51

EPSS

Процентиль: 16%
0.00051
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 6.5
nvd
5 месяцев назад

A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, and 2024.Q1.1 through 2024.Q1.12 is allow an remote non-authenticated attacker to reuse old user session by SLO API

EPSS

Процентиль: 16%
0.00051
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-613