<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 18:08:13 +0000</lastBuildDate>
    <item>
      <title>certfr-2025-avi-0815 — Une vulnérabilité a été découverte dans Liferay. Elle permet à un attaquant de provoquer un contournement de la politiq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0815</link>
      <description>certfr-2025-avi-0815</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0815</guid>
    </item>
    <item>
      <title>EUVD-2026-253355</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-253355</link>
      <description>EUVD-2026-253355</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-253355</guid>
    </item>
    <item>
      <title>fkie_cve-2025-43819</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-43819</link>
      <description>&lt;p&gt;A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, and 2024.Q1.1 through 2024.Q1.12 is allow an remote non-authenticated attacker to reuse old user session by SLO API&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, and 2024.Q1.1 through 2024.Q1.12 is allow an remote non-authenticated attacker to reuse old user session by SLO API&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-43819</guid>
    </item>
    <item>
      <title>GHSA-rpx3-f938-xj5q — Liferay Portal and DXP does not properly expire sessions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rpx3-f938-xj5q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.liferay:com.liferay.saml.impl&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Liferay Portal/DXP contains an Insufficient Session Expiration issue where the Single Logout (SLO) API may fail to invalidate a user’s previous session. An attacker can reuse a stale session via the SLO endpoint to gain an authenticated context.&lt;/p&gt;
&lt;p&gt;### Affected Versions&lt;/p&gt;
&lt;p&gt;The following platform versions are affected:&lt;/p&gt;
&lt;p&gt;*   **Liferay Portal:**  
    *   `7.3.3.131` through `7.4.3.121`
*   **Liferay DXP:**
    *   `2024.Q4.0`–`2024.Q4.3`
    *   `2024.Q3.1`–`2024.Q3.13`
    *   `2024.Q2.0`–`2024.Q2.13`
    *   `2024.Q1.1`–`2024.Q1.12`&lt;/p&gt;
&lt;p&gt;### Remediation&lt;/p&gt;
&lt;p&gt;Update to the fixed builds and, for Maven consumers of the SAML module, upgrade `com.liferay:com.liferay.saml.impl` to **5.0.51** or later. After upgrading, ensure session invalidation policies are enforced and verify SLO behavior end-to-end.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.liferay:com.liferay.saml.impl&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Liferay Portal/DXP contains an Insufficient Session Expiration issue where the Single Logout (SLO) API may fail to invalidate a user’s previous session. An attacker can reuse a stale session via the SLO endpoint to gain an authenticated context.&lt;/p&gt;
&lt;p&gt;### Affected Versions&lt;/p&gt;
&lt;p&gt;The following platform versions are affected:&lt;/p&gt;
&lt;p&gt;*   **Liferay Portal:**  
    *   `7.3.3.131` through `7.4.3.121`
*   **Liferay DXP:**
    *   `2024.Q4.0`–`2024.Q4.3`
    *   `2024.Q3.1`–`2024.Q3.13`
    *   `2024.Q2.0`–`2024.Q2.13`
    *   `2024.Q1.1`–`2024.Q1.12`&lt;/p&gt;
&lt;p&gt;### Remediation&lt;/p&gt;
&lt;p&gt;Update to the fixed builds and, for Maven consumers of the SAML module, upgrade `com.liferay:com.liferay.saml.impl` to **5.0.51** or later. After upgrading, ensure session invalidation policies are enforced and verify SLO behavior end-to-end.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rpx3-f938-xj5q</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2118 — Liferay Portal: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2118</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Liferay Portal und Liferay DXP ausnutzen, um Cross Site Scripting durchzuführen und Benutzerrechte erlangen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Liferay Portal und Liferay DXP ausnutzen, um Cross Site Scripting durchzuführen und Benutzerrechte erlangen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2118</guid>
    </item>
  </channel>
</rss>
