Liferay Portal and DXP does not properly expire sessions
Moderate severity
GitHub Reviewed
Published
Sep 24, 2025
to the GitHub Advisory Database
•
Updated Sep 27, 2025
Package
Affected versions
< 5.0.51
Patched versions
5.0.51
Description
Published by the National Vulnerability Database
Sep 24, 2025
Published to the GitHub Advisory Database
Sep 24, 2025
Reviewed
Sep 24, 2025
Last updated
Sep 27, 2025
Summary
Liferay Portal/DXP contains an Insufficient Session Expiration issue where the Single Logout (SLO) API may fail to invalidate a user’s previous session. An attacker can reuse a stale session via the SLO endpoint to gain an authenticated context.
Affected Versions
The following platform versions are affected:
7.3.3.131
through7.4.3.121
2024.Q4.0
–2024.Q4.3
2024.Q3.1
–2024.Q3.13
2024.Q2.0
–2024.Q2.13
2024.Q1.1
–2024.Q1.12
Remediation
Update to the fixed builds and, for Maven consumers of the SAML module, upgrade
com.liferay:com.liferay.saml.impl
to 5.0.51 or later. After upgrading, ensure session invalidation policies are enforced and verify SLO behavior end-to-end.References