
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-4655 is a Server-Side Request Forgery (SSRF) vulnerability in FreeMarker templates within Liferay Portal and Liferay DXP that allows authenticated template editors to bypass access validations via crafted URLs. It affects Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, and 7.4 GA through update 92. The vulnerability was published on August 9, 2025. It carries a CVSS v3.1 base score of 5.0 (Medium) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory, Liferay Advisory).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and resides in the FreeMarker template engine used by Liferay Portal and DXP. An attacker with template editing privileges can craft malicious URLs within FreeMarker templates that cause the server to make unauthorized outbound requests, bypassing the platform's built-in access validation controls. Exploitation requires low attack complexity and no user interaction beyond the attacker's own template editing access, but does require the attacker to hold template editor privileges on the platform (GitHub Advisory, Liferay Advisory).
Successful exploitation allows an authenticated template editor to make the Liferay server issue unauthorized server-side HTTP requests to internal or external resources, potentially exposing sensitive information from internal network services, cloud metadata endpoints, or other backend systems not directly accessible to the attacker. The primary impact is a low-level confidentiality breach on subsequent systems, with no direct integrity or availability impact on the vulnerable system itself. The scope change (S:C in CVSS v3.1) indicates that the impact extends beyond the vulnerable component to other systems reachable from the server (GitHub Advisory).
There is no public proof-of-concept exploit code available, and no evidence of in-the-wild exploitation has been reported as of the time of publication (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.036% (0.000360), placing it in the 38th percentile for exploitation probability within 30 days, indicating a low near-term exploitation likelihood (GitHub Advisory). Exploitation requires an attacker to already possess template editing privileges within the Liferay platform, which limits the attack surface.
http://169.254.169.254/latest/meta-data/) or an internal service, using a crafted URL that bypasses Liferay's access validation logic.freemarker.template.utility.Execute, URL-based includes, or similar constructs) that reference internal or metadata service addresses.Liferay has released patched versions addressing this vulnerability: Liferay DXP 2025.Q1.6 and 2024.Q1.16 are confirmed fixed versions (GitHub Advisory). Organizations should upgrade to the latest available patched release for their respective DXP or Portal branch. As interim mitigations, restrict template editing permissions to only highly trusted users, implement network-level egress filtering to prevent the Liferay server from making unauthorized outbound requests to internal resources, and audit existing templates for suspicious URL-fetching directives (Liferay Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."