Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25629 | Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet |
Github GHSA |
GHSA-23w4-rpc6-wpcc | Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 25 Aug 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 24 Aug 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liferay
Liferay dxp Liferay portal |
|
| Vendors & Products |
Liferay
Liferay dxp Liferay portal |
Sat, 23 Aug 2025 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScript in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.1, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92, which allows authenticated users with permissions to update Kaleo Workflows to enter a malicious Regex pattern causing their browser to hang for a very long time. | |
| Weaknesses | CWE-1333 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Liferay
Published:
Updated: 2025-08-25T18:44:21.917Z
Reserved: 2025-04-17T10:55:26.804Z
Link: CVE-2025-43764
Updated: 2025-08-25T18:44:18.474Z
Status : Awaiting Analysis
Published: 2025-08-23T05:15:30.667
Modified: 2025-08-25T20:24:45.327
Link: CVE-2025-43764
No data.
OpenCVE Enrichment
Updated: 2025-08-23T17:27:24Z
EUVD
Github GHSA