Self-ReDoS Vulnerability in Liferay Portal and DXP Affecting Kaleo Designer Portlet
CVE-2025-43764
6.9MEDIUM
What is CVE-2025-43764?
A vulnerability exists in the Kaleo Designer portlet of Liferay Portal and Liferay DXP, allowing authenticated users with update permissions to input malicious regular expressions. When these expressions are executed, they can lead to Denial of Service conditions, causing the user's browser to become unresponsive for extended periods. This vulnerability affects various versions of Liferay Portal and Liferay DXP, highlighting the importance of secure coding practices and proactive vulnerability management.
Affected Version(s)
DXP 7.4.13 <= 7.4.13-u92
DXP 2024.Q1.1 <= 2024.Q1.20
DXP 2024.Q2.1 <= 2024.Q2.13