CVE-2025-43764
published 2025-08-23CVE-2025-43764: Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScript in Liferay Portal 7.4.0 through…
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.29%
21.0th percentile
Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScript in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.1, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92, which allows authenticated users with permissions to update Kaleo Workflows to enter a malicious Regex pattern causing their browser to hang for a very long time.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | 2024.Q1.1 – 2024.Q1.20 | — |
| liferay | digital_experience_platform | >= 2024.Q4.0 < 2024.Q4.2 | 2024.Q4.2 |
| liferay | digital_experience_platform | 2024.q2.0 – 2024.q2.13 | — |
| liferay | digital_experience_platform | 2024.q3.1 – 2024.q3.13 | — |
| liferay | dxp | 2024.Q1.1 – 2024.Q1.20 | — |
| liferay | dxp | 2024.Q2.1 – 2024.Q2.13 | — |
| liferay | dxp | 2024.Q3.0 – 2024.Q3.13 | — |
| liferay | dxp | 2024.Q4.0 – 2024.Q4.1 | — |
| liferay | dxp | 7.4.13 – 7.4.13-u92 | — |
| liferay | liferay_portal | >= 7.4.0 < 7.4.3.132 | 7.4.3.132 |
| liferay | portal | 7.4.3.0 – 7.4.3.131 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet
osv·2025-08-23
CVE-2025-43764 [MEDIUM] Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet
Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet
Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScript in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.1, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92, which allows authenticated users with permissions to update Kaleo Workflows to enter a malicious Regex pattern causing their browser to hang for a very long time.
GHSA
Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet
ghsa·2025-08-23
CVE-2025-43764 [MEDIUM] CWE-1333 Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet
Liferay Portal ReDoS with Role Name search in KaleoDesignerPortlet
Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScript in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.1, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 and 7.4 GA through update 92, which allows authenticated users with permissions to update Kaleo Workflows to enter a malicious Regex pattern causing their browser to hang for a very long time.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-23
Published