Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows local users to view user email address in the log files.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liferay
Liferay dxp Liferay portal |
|
| Vendors & Products |
Liferay
Liferay dxp Liferay portal |
Mon, 27 Oct 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows local users to view user email address in the log files. | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Liferay
Published: 2025-10-27T20:39:23.416Z
Updated: 2025-10-28T14:41:31.296Z
Reserved: 2025-10-09T20:58:53.011Z
Link: CVE-2025-62262
Updated: 2025-10-28T14:35:38.375Z
Status : Received
Published: 2025-10-27T21:15:37.577
Modified: 2025-10-27T21:15:37.577
Link: CVE-2025-62262
No data.