A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure domain validation on analytics.cloud.domain.allowed, allowing an attacker to perform requests by change the domain and bypassing the validation method, this insecure validation is not distinguishing between trusted subdomains and malicious domains.
History

Thu, 21 Aug 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 21 Aug 2025 20:45:00 +0000

Type Values Removed Values Added
Description A server-side request forgery (SSRF) vulnerability exists in the Liferay DXP 2025.Q2.0 through 2025.Q2.3 due to insecure domain validation on analytics.cloud.domain.allowed, allowing an attacker to perform requests by change the domain and bypassing the validation method, this insecure validation is not distinguishing between trusted subdomains and malicious domains.
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Liferay

Published: 2025-08-21T20:23:20.040Z

Updated: 2025-08-21T20:52:21.478Z

Reserved: 2025-04-17T10:55:23.317Z

Link: CVE-2025-43747

cve-icon Vulnrichment

Updated: 2025-08-21T20:52:18.879Z

cve-icon NVD

Status : Received

Published: 2025-08-21T21:15:35.463

Modified: 2025-08-21T21:15:35.463

Link: CVE-2025-43747

cve-icon Redhat

No data.