CVE-2025-43754
unknown
CVSS v3
—
CVSS v2
—
VIR risk
—
Description
Liferay Portal Username Enumeration Vulnerability
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | com.liferay.portal:release.portal.bom | >=7.4.0-ga1,<=7.4.3.132-ga132 | |
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-43754
- https://github.com/liferay/liferay-portal/commit/f25bb9583f059f86937649fdacf940928ca3767b
- https://github.com/liferay/liferay-portal/commit/c8041d0f527388305897ac79f98d012bb31b82ac
- https://github.com/liferay/liferay-portal/commit/9ce8b8dec237f9b9049760904fcefd06a8695832
- https://github.com/liferay/liferay-portal/commit/9b4be82e964e9bbab1ce9824a61d9f40b28f38bb
- https://github.com/liferay/liferay-portal/commit/862ca74aaf98c70823022b6556cdc8a339128f79
- https://github.com/liferay/liferay-portal/commit/7118e956516d48792fb9365d1ae1f0ee971a8ac3
- https://github.com/liferay/liferay-portal/commit/6fdbb052a6e0cbe8b300138fb75f88df69f58799
- https://github.com/liferay/liferay-portal/commit/6f6f9f0922f6a13e21236915b864e0c1c12e47a9
- https://github.com/liferay/liferay-portal/commit/6629bb176c1f58ca852d599c013bd3e97b3312d3
- https://github.com/liferay/liferay-portal/commit/5b1bf48b0dc2a062928237ab1ea4a2274c63e652
- https://github.com/liferay/liferay-portal/commit/556450752159503476635c44736721ad797fa431
- https://github.com/liferay/liferay-portal/commit/53e6dcaa31a7599df8de9d3cef92e59e95a2064e
- https://github.com/liferay/liferay-portal/commit/45c3ca76966ddfaf8fe650f28910b0f55536f2b4
- https://github.com/liferay/liferay-portal/commit/38c0a06cebf0d635aa2af9912c068217161fcf1e
- https://github.com/liferay/liferay-portal/commit/367dc7d19aa31eaf881f217ceff9610f1747e2d7
- https://github.com/liferay/liferay-portal/commit/33697cf599a2c573ef9571696af55476ecc2ada6
- https://github.com/liferay/liferay-portal/commit/18a88af5409a5085cb094f5bc55229d5e03a9f29
- https://github.com/liferay/liferay-portal/commit/06b603671f0e76cd50f56d803a310a3c79944d1d
- https://liferay.atlassian.net/browse/LPE-18149
- https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-43754
- https://github.com/liferay/liferay-portal
- http://github.com/liferay/liferay-portal/commit/8199c568a66d66d6ad7ac450d3c69f6e0e9bd181
Verify integrity in audit chain (admin only). AS-IS.