Liferay Portal/DXP contains an Insufficient Session Expiration issue where the Single Logout (SLO) API may fail to invalidate a user’s previous session. An attacker can reuse a stale session via the SLO endpoint to gain an authenticated context.
The following platform versions are affected:
7.3.3.131 through 7.4.3.1212024.Q4.0–2024.Q4.32024.Q3.1–2024.Q3.132024.Q2.0–2024.Q2.132024.Q1.1–2024.Q1.12Update to the fixed builds and, for Maven consumers of the SAML module, upgrade com.liferay:com.liferay.saml.impl to 5.0.51 or later. After upgrading, ensure session invalidation policies are enforced and verify SLO behavior end-to-end.
{
    "nvd_published_at": "2025-09-24T02:15:31Z",
    "severity": "MODERATE",
    "cwe_ids": [
        "CWE-613"
    ],
    "github_reviewed_at": "2025-09-24T17:28:45Z",
    "github_reviewed": true
}