CVE-2025-43777

Description

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.19 exposes Internal Server Error in the response body when a login attempt is made with a deleted Client Secret.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.042

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2025-43777 are fixed in Liferay - com.liferay.portal.security.sso.openid.connect.impl 7.0.48Windows
Vulnerabilities CVE-2025-43777 are fixed in Liferay - com.liferay.portal.security.sso.openid.connect.impl for Linux 7.0.48Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234