iferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA through update 92 allows a pre-authentication blind SSRF vulnerability in the portal-settings-authentication-opensso-web due to improper validation of user-supplied URLs. An attacker can exploit this issue to force the server to make arbitrary HTTP requests to internal systems, potentially leading to internal network enumeration or further exploitation.
| Link | Resource |
|---|---|
| https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-4581 | Vendor Advisory |
Configuration 1 (hide)
|
16 Dec 2025, 16:43
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-4581 - Vendor Advisory | |
| CPE | cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:*:*:*:*:*:*:* |
|
| First Time |
Liferay digital Experience Platform
Liferay Liferay liferay Portal |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.6 |
11 Aug 2025, 18:32
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-08-09 05:15
Updated : 2025-12-16 16:43
NVD link : CVE-2025-4581
Mitre link : CVE-2025-4581
CVE.ORG link : CVE-2025-4581
JSON object : View
Server-Side Request Forgery (SSRF)