The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions uses an incorrect cache-control header, which allows local users to obtain access to downloaded files via the browser's cache.
CVSS
No CVSS.
References
Configurations
No configuration.
History
01 Nov 2025, 00:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-01 00:15
Updated : 2025-11-04 15:41
NVD link : CVE-2025-62276
Mitre link : CVE-2025-62276
CVE.ORG link : CVE-2025-62276
JSON object : View
Products Affected
No product.
CWE
CWE-525
Use of Web Browser Cache Containing Sensitive Information
