The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions uses an incorrect cache-control header, which allows local users to obtain access to downloaded files via the browser's cache.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Nov 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Nov 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liferay
Liferay dxp Liferay portal |
|
| Vendors & Products |
Liferay
Liferay dxp Liferay portal |
Fri, 31 Oct 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions uses an incorrect cache-control header, which allows local users to obtain access to downloaded files via the browser's cache. | |
| Weaknesses | CWE-525 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Liferay
Published: 2025-10-31T23:34:20.166Z
Updated: 2025-11-03T13:31:38.847Z
Reserved: 2025-10-09T20:58:54.403Z
Link: CVE-2025-62276
Updated: 2025-11-03T13:10:52.622Z
Status : Awaiting Analysis
Published: 2025-11-01T00:15:33.387
Modified: 2025-11-04T15:41:31.450
Link: CVE-2025-62276
No data.