CVE-2025-62276
The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions uses an incorrect cache-control header, which allows local users to obtain access to downloaded files via the browser's cache.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.6
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.13%
- CWE
- CWE-525
- Published
- 2025-10-31
- Last modified
- 2026-03-12
Affected products
- Liferay Portal
- Liferay DXP
- Liferay DXP
- Liferay DXP
Weakness type
Related vulnerabilities
- CVE-2026-13697 — undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
- CVE-2024-23571 — HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate...
- CVE-2026-41918 — A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0)....
- CVE-2026-41322 — @astrojs/node: Cache Poisoning due to incorrect error handling when if-match header is malformed
- CVE-2025-15554 — Admin Passwords Cached by Browsers in Truesec LAPSWebUI
- CVE-2025-36364 — IBM DevOps Plan REST APIs are vulnerable to exposure of sensitive data through request query parameters.
- CVE-2026-27514 — Tenda F3 Plaintext Credential Exposure in Configuration Download
- CVE-2026-24437 — Tenda W30E V2 Missing Cache Controls for Credential-bearing Pages