
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62266 is a DNS rebinding vulnerability in Liferay Portal and Liferay DXP that allows remote attackers to redirect users to arbitrary external URLs. It affects Liferay Portal 7.4.0 through 7.4.3.119 (and older unsupported versions), and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 (and older unsupported versions). The vulnerability was published on October 30, 2025. It carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory, Liferay Security).
The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / Open Redirect). By default, Liferay's redirect URL security mechanism validates redirect targets based on IP address rather than domain name, making it susceptible to DNS rebinding attacks where an attacker can manipulate DNS resolution to bypass IP-based allowlists and redirect users to attacker-controlled external URLs. Exploitation requires no privileges and no special attack conditions, but does require active user interaction (a victim must follow a crafted link or be redirected). The vendor notes this can be mitigated by changing the redirect URL security setting from IP-based to domain-based validation (GitHub Advisory).
Successful exploitation allows a remote, unauthenticated attacker to redirect authenticated or unauthenticated users from a trusted Liferay Portal or DXP instance to an arbitrary external URL of the attacker's choosing. The primary risks are phishing attacks, credential harvesting, and social engineering, as users may trust a redirect originating from a known Liferay portal. Confidentiality and integrity impacts are rated low, with no availability impact; subsequent system impact is also none, limiting the scope to the user's browser session (GitHub Advisory).
Liferay has released a patched version of Liferay Portal (7.4.3.110 and later). For Liferay DXP, administrators should apply the relevant quarterly or update releases beyond the affected ranges. As an immediate workaround without upgrading, administrators should change the redirect URL security setting from IP to domain in the Liferay portal configuration, which prevents DNS rebinding from bypassing redirect validation. Organizations running older unsupported versions should prioritize upgrading to a supported, patched release (GitHub Advisory, Liferay Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."