CVE-2025-3602
EUVD-2025-1839816.06.2025, 14:15
Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and 7.2 fix pack 8 through fix pack 20 does not limit the depth of a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing complex queries.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| liferay | digital_experience_platform | 2023.q3.1 ≤ 𝑥 ≤ 2023.q3.2 |
| liferay | digital_experience_platform | 7.2:fix_pack_10 |
| liferay | digital_experience_platform | 7.2:fix_pack_11 |
| liferay | digital_experience_platform | 7.2:fix_pack_12 |
| liferay | digital_experience_platform | 7.2:fix_pack_13 |
| liferay | digital_experience_platform | 7.2:fix_pack_14 |
| liferay | digital_experience_platform | 7.2:fix_pack_15 |
| liferay | digital_experience_platform | 7.2:fix_pack_16 |
| liferay | digital_experience_platform | 7.2:fix_pack_17 |
| liferay | digital_experience_platform | 7.2:fix_pack_18 |
| liferay | digital_experience_platform | 7.2:fix_pack_19 |
| liferay | digital_experience_platform | 7.2:fix_pack_20 |
| liferay | digital_experience_platform | 7.2:fix_pack_8 |
| liferay | digital_experience_platform | 7.2:fix_pack_9 |
| liferay | digital_experience_platform | 7.3 |
| liferay | digital_experience_platform | 7.3:fix_pack_1 |
| liferay | digital_experience_platform | 7.3:fix_pack_2 |
| liferay | digital_experience_platform | 7.3:service_pack_1 |
| liferay | digital_experience_platform | 7.3:service_pack_2 |
| liferay | digital_experience_platform | 7.3:service_pack_3 |
| liferay | digital_experience_platform | 7.3:update1 |
| liferay | digital_experience_platform | 7.3:update10 |
| liferay | digital_experience_platform | 7.3:update11 |
| liferay | digital_experience_platform | 7.3:update12 |
| liferay | digital_experience_platform | 7.3:update13 |
| liferay | digital_experience_platform | 7.3:update14 |
| liferay | digital_experience_platform | 7.3:update15 |
| liferay | digital_experience_platform | 7.3:update16 |
| liferay | digital_experience_platform | 7.3:update17 |
| liferay | digital_experience_platform | 7.3:update18 |
| liferay | digital_experience_platform | 7.3:update19 |
| liferay | digital_experience_platform | 7.3:update2 |
| liferay | digital_experience_platform | 7.3:update20 |
| liferay | digital_experience_platform | 7.3:update21 |
| liferay | digital_experience_platform | 7.3:update22 |
| liferay | digital_experience_platform | 7.3:update23 |
| liferay | digital_experience_platform | 7.3:update24 |
| liferay | digital_experience_platform | 7.3:update25 |
| liferay | digital_experience_platform | 7.3:update26 |
| liferay | digital_experience_platform | 7.3:update27 |
| liferay | digital_experience_platform | 7.3:update28 |
| liferay | digital_experience_platform | 7.3:update29 |
| liferay | digital_experience_platform | 7.3:update3 |
| liferay | digital_experience_platform | 7.3:update30 |
| liferay | digital_experience_platform | 7.3:update31 |
| liferay | digital_experience_platform | 7.3:update32 |
| liferay | digital_experience_platform | 7.3:update33 |
| liferay | digital_experience_platform | 7.3:update34 |
| liferay | digital_experience_platform | 7.3:update35 |
| liferay | digital_experience_platform | 7.3:update4 |
| liferay | digital_experience_platform | 7.3:update5 |
| liferay | digital_experience_platform | 7.3:update6 |
| liferay | digital_experience_platform | 7.3:update7 |
| liferay | digital_experience_platform | 7.3:update8 |
| liferay | digital_experience_platform | 7.3:update9 |
| liferay | digital_experience_platform | 7.4 |
| liferay | liferay_portal | 7.4.0 ≤ 𝑥 ≤ 7.4.3.97 |
𝑥
= Vulnerable software versions