CVE-2025-43758
Liferay Portal's unauthenticated users can access loaded files via URL before submitting the object entry
EPSS 0.13%
Description
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows unauthenticated users (guests) to access via URL files uploaded by object entry and stored in document_library
How to fix CVE-2025-43758
To remediate CVE-2025-43758, upgrade the affected package to a fixed version below.
- Maven/com.liferay:com.liferay.frontend.js.web—upgrade to 5.0.125 or later
- —upgrade to 1.0.65 or later
- —upgrade to 1.0.219 or later
Is CVE-2025-43758 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 5.0.125
- from 0, < 1.0.65
- from 0, < 1.0.219
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N |