logo

CVE-2025-3594 com.liferay:com.liferay.server.admin.web

Package

Manager: maven
Name: com.liferay:com.liferay.server.admin.web
Vulnerable Version: >=5.0.0 <5.0.24 || >=4.0.0 <4.0.48 || >=3.0.0 <3.0.67 || >=2.0.0 <2.0.66 || >=0 <1.0.93

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00336 pctl0.55762

Details

Liferay Portal path traversal vulnerability with the downloading and installation of Xuggler Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older unsupported versions allows remote attackers to (1) add files to arbitrary locations on the server and (2) download and execute arbitrary files from the download server via the `_com_liferay_server_admin_web_portlet_ServerAdminPortlet_jarName` parameter.

Metadata

Created: 2025-06-16T15:32:28Z
Modified: 2025-06-16T17:49:54Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/06/GHSA-p73j-gpcq-49h8/GHSA-p73j-gpcq-49h8.json
CWE IDs: ["CWE-22"]
Alternative ID: GHSA-p73j-gpcq-49h8
Finding: F063
Auto approve: 1