Server-Side Request Forgery Vulnerability in Liferay Digital Experience Platform
CVE-2025-43747
What is CVE-2025-43747?
A server-side request forgery (SSRF) vulnerability exists in Liferay DXP from versions 2025.Q2.0 through 2025.Q2.3. This issue arises from inadequate validation of domains specified in the analytics.cloud.domain.allowed setting. As a consequence, an attacker can manipulate requests to bypass security checks, allowing potentially malicious domains to be treated as trusted. This vulnerability does not differentiate between legitimate subdomains and those that are harmful, opening avenues for exploitation that could lead to unauthorized access and data exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DXP 2025.Q2.0 <= 2025.Q2.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved