CVE-2025-43819 Details
Description
A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, and 2024.Q1.1 through 2024.Q1.12 is allow an remote non-authenticated attacker to reuse old user session by SLO API
A vulnerability allowing insufficient session expiration has been identified in Liferay Portal versions 7.4.3.121 through 7.3.3.131, as well as in Liferay DXP versions 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, and 2024.Q1.1 through 2024.Q1.12. This vulnerability allows remote, non-authenticated attackers to reuse old user sessions by exploiting the Single Logout (SLO) API.
Users can upgrade to Liferay Portal 7.4.3.132 or Liferay DXP versions 2025.Q1.0, 2024.Q1.13, or 2024.Q4.4 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-43819 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| liferay digital experience platform | >= 2024.Q1.1, < 2024.Q1.13 >= 2024.q2.0, <= 2024.q2.13 >= 2024.q3.1, <= 2024.q3.13 >= 2024.Q4.0, < 2024.Q4.4 7.4 |
CPE
Remediation
| |
| liferay liferay portal | >= 7.4.3.121, < 7.4.3.132 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 15, 2025 | Initial Analysis | [email protected] |
| Sep 24, 2025 | New CVE Received | [email protected] |