Liferay Portal
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*
- >= 7.4.0, <= 7.4.3.132
A pre-authentication blind server-side request forgery (SSRF) vulnerability has been identified in Liferay Portal versions 7.4.0 through 7.4.3.132, as well as in several Liferay DXP releases. The vulnerability arises in the 'portal-settings-authentication-opensso-web' component, due to inadequate validation of user-supplied URLs. This flaw allows attackers to manipulate the server into making arbitrary HTTP requests to internal systems, which could result in internal network enumeration or further exploitation.
Exploitation of this vulnerability could lead to unauthorized internal network access, allowing for network enumeration or additional exploitation of internal systems.
Users can upgrade to Liferay Portal's master branch or Liferay DXP versions 2025.Q2.0, 2025.Q1.5, or 2024.Q1.16 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.