Self-ReDoS Vulnerability in Liferay Portal and DXP Affecting Kaleo Designer Portlet
CVE-2025-43764

6.9MEDIUM

Key Information:

Vendor

Liferay

Status
Vendor
CVE Published:
23 August 2025

What is CVE-2025-43764?

A vulnerability exists in the Kaleo Designer portlet of Liferay Portal and Liferay DXP, allowing authenticated users with update permissions to input malicious regular expressions. When these expressions are executed, they can lead to Denial of Service conditions, causing the user's browser to become unresponsive for extended periods. This vulnerability affects various versions of Liferay Portal and Liferay DXP, highlighting the importance of secure coding practices and proactive vulnerability management.

Affected Version(s)

DXP 7.4.13 <= 7.4.13-u92

DXP 2024.Q1.1 <= 2024.Q1.20

DXP 2024.Q2.1 <= 2024.Q2.13

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-43764 : Self-ReDoS Vulnerability in Liferay Portal and DXP Affecting Kaleo Designer Portlet