CVE-2025-62275
Java vulnerability analysis and mitigation

Overview

CVE-2025-62275 is an incorrect authorization vulnerability in the Blogs component of Liferay Portal and Liferay DXP that allows unauthenticated remote attackers to view restricted images in blog entries via a crafted URL. It affects Liferay Portal versions 7.4.0 through 7.4.3.111 (and older unsupported versions), and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 (and older unsupported versions). The vulnerability was disclosed on November 1, 2025, with NVD initial analysis completed on November 10, 2025. It carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, Liferay Advisory).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization): the Blogs module in affected Liferay versions fails to perform permission checks when serving images embedded in blog entries. An attacker can construct a crafted URL pointing directly to a blog entry image resource, bypassing the access control logic that would normally restrict visibility based on the blog entry's permissions. No authentication, special privileges, or user interaction is required to exploit this flaw. The vulnerable Maven package is com.liferay:com.liferay.blogs.item.selector.web, with versions below 6.0.19 affected; the fix was introduced in version 6.0.19 (GitHub Advisory, Liferay Advisory).

Impact

Successful exploitation results in unauthorized disclosure of images embedded in blog entries that should be restricted to specific users or roles. The impact is limited to confidentiality — there is no integrity or availability impact — but sensitive or private visual content (e.g., internal documents, proprietary diagrams, or personal images) could be exposed to any unauthenticated internet user. The vulnerability does not enable lateral movement, code execution, or data modification, but it may contribute to broader information disclosure in environments where blog entries contain sensitive imagery (GitHub Advisory, Liferay Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Feedly). No threat actor attribution has been reported. The EPSS score is approximately 0.058% (18th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is straightforward in concept — requiring only a crafted URL with no authentication — but the limited impact (image disclosure only) reduces attacker incentive (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify Liferay Portal or DXP instances running affected versions (7.4.0–7.4.3.111 for Portal; 2023.Q3.1–2023.Q3.10 or 2023.Q4.0–2023.Q4.10 for DXP) using tools like Shodan, Censys, or by inspecting HTTP response headers and page metadata.
  2. Identify blog entries: Browse publicly accessible blog listings on the target Liferay instance to enumerate blog entries and identify image URLs embedded within them.
  3. Extract image resource URLs: Inspect the HTML source or network traffic of blog entry pages to identify direct URLs to images that are associated with restricted or private blog entries.
  4. Craft access URL: Construct or directly use the image resource URL (e.g., referencing the document library or blog image endpoint) without any authentication token or session cookie.
  5. Access restricted images: Submit the crafted URL via a standard HTTP GET request; the server returns the image without performing a permission check, exposing content that should be restricted (GitHub Advisory, Liferay Advisory).

Indicators of compromise

  • Network: Unauthenticated HTTP GET requests to Liferay blog image endpoints (e.g., URLs containing /documents/, /image/, or blog-related image paths) originating from external or unexpected IP addresses, particularly without a valid session cookie.
  • Logs: Liferay access logs showing repeated requests to blog image resources from unauthenticated sessions (no JSESSIONID or equivalent session token); high volume of image resource requests from a single IP or user agent.
  • Logs: HTTP 200 responses served to unauthenticated requests for resources that should require authentication, particularly for blog entry image paths.
  • Behavioral: Systematic enumeration of blog image URLs (sequential or pattern-based URL requests) suggesting automated scraping of restricted content.

Mitigation and workarounds

Liferay has released patches addressing this vulnerability. Users should upgrade the com.liferay:com.liferay.blogs.item.selector.web Maven package to version 6.0.19 or later. For Liferay Portal, upgrade to version 7.4.3.112 or later; for Liferay DXP, upgrade beyond 2023.Q4.10 or 2023.Q3.10 to a fixed quarterly release. As interim mitigations, administrators should implement additional network-level access controls (e.g., WAF rules or reverse proxy authentication) for blog image endpoints, audit existing blog entries for sensitive images, and monitor access logs for unauthorized image retrieval attempts (GitHub Advisory, Liferay Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-73493HIGH7.5
  • Java logoJava
  • org.http4s:http4s-blaze-server_2.12
NoYesAug 12, 2026
CVE-2026-48048HIGH7.5
  • Java logoJava
  • org.xwiki.platform:xwiki-platform-livetable-ui
NoYesAug 10, 2026
CVE-2026-73495HIGH7.4
  • Java logoJava
  • org.http4s:blaze-http_2.12
NoYesAug 12, 2026
CVE-2026-48047MEDIUM5.9
  • Java logoJava
  • org.xwiki.platform:xwiki-platform-webjars-api
NoYesAug 07, 2026
CVE-2026-48791LOW2
  • Java logoJava
  • dev.sigstore:sigstore-java
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management