
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-43768 is an information disclosure vulnerability in Liferay Portal and Liferay DXP that allows authenticated users with low-level permissions to access sensitive information belonging to admin users via JSONWS APIs. It affects Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, and 7.4 GA through update 92. The vulnerability was published on August 23, 2025, and a patch was made available the same day. It carries a CVSS v3.1 base score of 7.7 (High) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory, Red Hat).
The root cause is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data), where the JSONWS API endpoints in Liferay Portal and DXP transmit sensitive administrative user data to actors who should not have access to it. An authenticated attacker with minimal (low-level) privileges can craft API requests to JSONWS endpoints that return sensitive information about admin users, exploiting the lack of proper authorization checks on those endpoints. The vulnerability requires no special configuration or elevated privileges beyond a basic authenticated session, and no user interaction from an administrator is needed. A fix commit is available in the liferay-portal repository (efdbdbc) and tracked under Liferay issue LPE-18154 (GitHub Advisory).
Successful exploitation results in unauthorized disclosure of sensitive administrative user information, including data that should be restricted to privileged accounts. While there is no integrity or availability impact, the exposed information could be leveraged for targeted attacks, privilege escalation attempts, or reconnaissance against the affected Liferay instance. The changed scope in the CVSS v3.1 rating indicates that the impact extends beyond the directly vulnerable component, potentially affecting other systems or users within the environment (GitHub Advisory, Red Hat).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.034% (0.000340), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only a low-privilege authenticated account, which lowers the barrier for any attacker who can register or obtain credentials on the target platform.
/api/jsonws) to enumerate available API methods, focusing on those that return user-related data./api/jsonws endpoints from low-privilege user accounts; requests querying user-related API methods (e.g., user/get-user-by-id, user/get-users) from accounts that do not normally access these endpoints.Liferay has released a patch addressing this vulnerability; for Liferay Portal, upgrade to version 7.4.3.132 or later, and for the Maven package com.liferay.portal:com.liferay.portal.impl, upgrade to version 108.1.1 or later. For Liferay DXP, upgrade to 2024.Q1.16+, 2024.Q4.8+, or the next available fixed quarterly release. As a temporary workaround if immediate patching is not possible, restrict or disable JSONWS API access at the network or application layer, implement strict access controls, and audit existing user permissions. Monitoring and auditing API access logs is also recommended (GitHub Advisory, Liferay Advisory).
The vulnerability was noted by automated CVE tracking accounts on X (formerly Twitter) shortly after disclosure. Red Hat published a security advisory tracking the CVE. No significant researcher commentary, vendor blog posts, or major media coverage has been identified beyond standard vulnerability database entries (Red Hat).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."