Home
MEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
7.4.0 (maven)
affected
Default status
unaffected
7.3.10 (maven)
affected
7.4.13 (maven)
affected
2023.Q4.0 (maven)
affected
2023.Q3.1 (maven)
affected
Description
Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly restrict access to OpenAPI in certain circumstances, which allows remote attackers to access the OpenAPI YAML file via a crafted URL.
Problem types
Product status
7.4.0 (maven)
7.3.10 (maven)
7.4.13 (maven)
2023.Q4.0 (maven)
2023.Q3.1 (maven)
References
liferay.dev/...-/asset_publisher/jekt/content/CVE-2025-62256
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.