
Cloud Vulnerability DB
A community-led vulnerabilities database
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP versions from 2024.Q1.1 through 2025.Q2.9 contain a vulnerability that exposes 'Internal Server Error' in the response body when a login attempt is made with a deleted Client Secret (Liferay Dev).
The vulnerability has been assigned a CVSS v4.0 score of 5.1 with the vector string CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N, indicating a medium severity issue. The vulnerability is triggered when attempting to login using a deleted Client Secret, which results in an exposed internal server error message in the response body (Liferay Dev).
The exposure of internal server error messages could potentially reveal sensitive system information to attackers, which could be used to gather intelligence about the system architecture or implementation details (Liferay Dev).
The vulnerability has been fixed in multiple versions: Liferay Portal fixed on master branch, Liferay DXP 2024.Q1.20, Liferay DXP 2025.Q1.17, and Liferay DXP 2025.Q2.10. Users are advised to upgrade to these fixed versions to mitigate the vulnerability (Liferay Dev).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."