CVE-2025-62276
MEDIUMDescription
The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions uses an incorrect cache-control header, which allows local users to obtain access to downloaded files via the browser's cache.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | digital_experience_platform |
| liferay | liferay_portal |
References
Frequently Asked Questions
What is CVE-2025-62276? +
How severe is CVE-2025-62276? +
What products are affected by CVE-2025-62276? +
How do I check if I'm vulnerable to CVE-2025-62276? +
Related Vulnerabilities
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In Auth0 Next.js SDK versions 4.0.1 …
IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on …
Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow. Airflow did not return "Cache-Control" header for dynamic …
@astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resources from …
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows web pages to …
IBM Sterling Control Center 6.2.1, 6.3.1, and 6.4.0 allows web pages to be stored locally which can be read by …