The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions uses an incorrect cache-control header, which allows local users to obtain access to downloaded files via the browser's cache.
PUBLISHED5.2CWE-525
Problem type
Affected products
Liferay
Portal
<= 7.4.3.111 - AFFECTED
DXP
<= 7.4.13-u92 - AFFECTED
<= 2023.Q3.10 - AFFECTED
<= 2023.Q4.10 - AFFECTED
References
JSON source
Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2025-62276",
"assignerOrgId": "8b54e794-c6f0-462e-9faa-c1001a673ac3",
"assignerShortName": "Liferay",
"dateUpdated": "2025-10-31T23:34:20.166Z",
"dateReserved": "2025-10-09T20:58:54.403Z",
"datePublished": "2025-10-31T23:34:20.166Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "8b54e794-c6f0-462e-9faa-c1001a673ac3",
"shortName": "Liferay",
"dateUpdated": "2025-10-31T23:34:20.166Z"
},
"descriptions": [
{
"lang": "en",
"value": "The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions uses an incorrect cache-control header, which allows local users to obtain access to downloaded files via the browser's cache.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions uses an incorrect cache-control header, which allows local users to obtain access to downloaded files via the browser's cache."
}
]
}
],
"affected": [
{
"vendor": "Liferay",
"product": "Portal",
"defaultStatus": "unaffected",
"versions": [
{
"version": "7.4.0",
"status": "affected",
"versionType": "maven",
"lessThanOrEqual": "7.4.3.111"
}
]
},
{
"vendor": "Liferay",
"product": "DXP",
"defaultStatus": "unaffected",
"versions": [
{
"version": "7.4.13",
"status": "affected",
"versionType": "maven",
"lessThanOrEqual": "7.4.13-u92"
},
{
"version": "2023.Q3.1",
"status": "affected",
"versionType": "maven",
"lessThanOrEqual": "2023.Q3.10"
},
{
"version": "2023.Q4.0",
"status": "affected",
"versionType": "maven",
"lessThanOrEqual": "2023.Q4.10"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-525: Use of Web Browser Cache Containing Sensitive Information",
"cweId": "CWE-525",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-62276"
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
]
}
}
}