GHSA-q86r-gwqc-jx85

Suggest an improvement
Source
https://github.com/advisories/GHSA-q86r-gwqc-jx85
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-q86r-gwqc-jx85/GHSA-q86r-gwqc-jx85.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q86r-gwqc-jx85
Aliases
  • CVE-2025-43789
Published
2025-09-12T03:33:06Z
Modified
2025-09-15T13:59:44.861068Z
Severity
  • 1.0 (Low) CVSS_V4 - CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Liferay Portal JSON Web Services Direct Class Invocation Enables Service Access Policy Execution
Details

JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through update 92 published to OSGi are registered and invoked directly as classes which allows Service Access Policies to get executed.

Database specific
{
    "nvd_published_at": "2025-09-12T03:15:41Z",
    "severity": "LOW",
    "cwe_ids": [
        "CWE-863"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-09-15T13:46:34Z"
}
References

Affected packages

Maven / com.liferay:com.liferay.comment.web

Package

Name
com.liferay:com.liferay.comment.web
View open source insights on deps.dev
Purl
pkg:maven/com.liferay/com.liferay.comment.web

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.2
Fixed
6.1.4

Affected versions

6.*

6.0.2
6.0.3
6.0.4
6.0.5
6.0.6
6.0.7
6.0.8
6.0.9
6.0.10
6.0.11
6.0.12
6.0.13
6.0.14
6.0.15
6.0.16
6.0.17
6.0.18
6.0.19
6.0.20
6.0.21
6.0.22
6.0.23
6.0.24
6.1.0
6.1.1
6.1.2
6.1.3