Liferay Portal and DXP Subdomain Misidentification Leading to Supercookie Vulnerability

Vulnerability

A vulnerability exists in Liferay Portal versions 7.4.0 to 7.4.3.105, older unsupported versions, and Liferay DXP versions 2023.Q4.0, 2023.Q3.1 to 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions. This vulnerability may cause incorrect subdomain identification, leading to the creation of a supercookie. This supercookie allows remote attackers controlling websites with the same top-level domain to read cookies set by the application.

Impact

Exploitation of this vulnerability allows remote attackers to read application-set cookies from users who visit their website, potentially leading to session hijacking or other attacks that rely on cookie data.

Remediation

Users can upgrade to Liferay Portal 7.4.3.106 or Liferay DXP versions 2024.Q1.1, 2023.Q4.1, 2023.Q3.5, or 7.3 U36 to address this vulnerability.

Added: Sep 15, 2025, 7:28 PM
Updated: Sep 15, 2025, 7:28 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
3.3
exploitability
6.4
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.