Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows a pre-authentication blind SSRF vulnerability in the portal-settings-authentication-opensso-web due to improper validation of user-supplied URLs. An attacker can exploit this issue to force the server to make arbitrary HTTP requests to internal systems, potentially leading to internal network enumeration or further exploitation.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "2024.q1.1"
},
{
"last_affected": "2024.q1.15"
},
{
"introduced": "2024.q2.0"
},
{
"last_affected": "2024.q2.13"
},
{
"introduced": "2024.q3.1"
},
{
"last_affected": "2024.q3.13"
},
{
"introduced": "2024.q4.0"
},
{
"last_affected": "2024.q4.7"
},
{
"introduced": "2025.q1.0"
},
{
"last_affected": "2025.q1.4"
}
],
"source": "CPE_RANGE",
"vendor_product": "liferay:digital_experience_platform"
},
{
"cpes": [
"cpe:2.3:a:liferay:digital_experience_platform:7.4:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "7.4"
},
{
"last_affected": "7.4"
}
],
"source": "CPE_STRING",
"vendor_product": "liferay:digital_experience_platform"
}
]
}