Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. com.liferay.portal/release.portal.bom
  4. ›
  5. CVE-2025-62257

CVE-2025-62257: Liferay Portal vulnerable to password enumeration

October 30, 2025

Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote attackers to determine a user’s password even if account lockout is enabled via brute force attack.

References

  • github.com/advisories/GHSA-8hw3-ghwv-crfh
  • github.com/liferay/liferay-portal
  • github.com/liferay/liferay-portal/commit/45cffd5030ab78e8b005d9cfd6284311da978c68
  • github.com/liferay/liferay-portal/commit/924a0a47007665693fe2d29623cb48a426a80266
  • github.com/liferay/liferay-portal/commit/d21627ac07561c5063f611be631e63ff502ec8e7
  • liferay.atlassian.net/browse/LPE-17692
  • liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-62257
  • nvd.nist.gov/vuln/detail/CVE-2025-62257

Code Behaviors & Features

Detect and mitigate CVE-2025-62257 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 7.4.0-ga1 before 7.4.3.120

Fixed versions

  • 7.4.3.120

Solution

Upgrade to version 7.4.3.120 or above.

Weakness

  • CWE-307: Improper Restriction of Excessive Authentication Attempts

Source file

maven/com.liferay.portal/release.portal.bom/CVE-2025-62257.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 15 Nov 2025 00:18:39 +0000.