Логотип exploitDog
bind:CVE-2025-62256
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-62256

Количество 2

Количество 2

nvd логотип

CVE-2025-62256

4 месяца назад

Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly restrict access to OpenAPI in certain circumstances, which allows remote attackers to access the OpenAPI YAML file via a crafted URL.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-j82q-c85j-xw4w

4 месяца назад

Liferay Portal and DXP do not properly restrict access to OpenAPI

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-62256

Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly restrict access to OpenAPI in certain circumstances, which allows remote attackers to access the OpenAPI YAML file via a crafted URL.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-j82q-c85j-xw4w

Liferay Portal and DXP do not properly restrict access to OpenAPI

CVSS3: 5.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу