Liferay Portal/DXP contains an Insufficient Session Expiration issue where the Single Logout (SLO) API may fail to invalidate a user’s previous session. An attacker can reuse a stale session via the SLO endpoint to gain an authenticated context.
The following platform versions are affected:
7.3.3.131
through 7.4.3.121
2024.Q4.0
–2024.Q4.3
2024.Q3.1
–2024.Q3.13
2024.Q2.0
–2024.Q2.13
2024.Q1.1
–2024.Q1.12
Update to the fixed builds and, for Maven consumers of the SAML module, upgrade com.liferay:com.liferay.saml.impl
to 5.0.51 or later. After upgrading, ensure session invalidation policies are enforced and verify SLO behavior end-to-end.
{ "cwe_ids": [ "CWE-613" ], "nvd_published_at": "2025-09-24T02:15:31Z", "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-09-24T17:28:45Z" }