Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. com.liferay/com.liferay.site.navigation.menu.item.asset.vocabulary
  4. ›
  5. CVE-2025-62251

CVE-2025-62251: Liferay has Incorrect Permission Assignment for Critical Resource

October 14, 2025 (updated October 15, 2025)

Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA through update 92 and 7.3 GA though update 36 shows content to users who do not have permission to view it via the Menu Display Widget. This security flaw could result in sensitive information being exposed to unauthorized users.

References

  • github.com/advisories/GHSA-j4f7-gj7q-xg9m
  • github.com/liferay/liferay-portal
  • github.com/liferay/liferay-portal/commit/12bec829da315c21fbc96492ffbdda4c7a2e59cb
  • liferay.atlassian.net/browse/LPE-18236
  • liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-62251
  • nvd.nist.gov/vuln/detail/CVE-2025-62251

Code Behaviors & Features

Detect and mitigate CVE-2025-62251 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.0.23

Fixed versions

  • 1.0.23

Solution

Upgrade to version 1.0.23 or above.

Weakness

  • CWE-732: Incorrect Permission Assignment for Critical Resource

Source file

maven/com.liferay/com.liferay.site.navigation.menu.item.asset.vocabulary/CVE-2025-62251.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Fri, 07 Nov 2025 00:19:15 +0000.