CVE-2025-3594 – com.liferay:com.liferay.server.admin.web
Package
Manager: maven
Name: com.liferay:com.liferay.server.admin.web
Vulnerable Version: >=5.0.0 <5.0.24 || >=4.0.0 <4.0.48 || >=3.0.0 <3.0.67 || >=2.0.0 <2.0.66 || >=0 <1.0.93
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00336 pctl0.55762
Details
Liferay Portal path traversal vulnerability with the downloading and installation of Xuggler Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older unsupported versions allows remote attackers to (1) add files to arbitrary locations on the server and (2) download and execute arbitrary files from the download server via the `_com_liferay_server_admin_web_portlet_ServerAdminPortlet_jarName` parameter.
Metadata
Created: 2025-06-16T15:32:28Z
Modified: 2025-06-16T17:49:54Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/06/GHSA-p73j-gpcq-49h8/GHSA-p73j-gpcq-49h8.json
CWE IDs: ["CWE-22"]
Alternative ID: GHSA-p73j-gpcq-49h8
Finding: F063
Auto approve: 1