CVE-2025-3586

HIGH

Liferay DXP 2023.Q3.1-2023.Q3.10 Authenticated RCE via Groovy Script

Title source: llm
STIX 2.1

Description

In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 27 through update 42 (Liferay PaaS, and Liferay Self-Hosted), the Objects module does not restrict the use of Groovy scripts in Object actions for Admin Users. This allows remote authenticated admin users with the Instance Administrator role to execute arbitrary Groovy scripts (i.e., remote code execution) through Object actions. In contrast, in Liferay DXP (Liferay SaaS), the use of Groovy in Object actions is not allowed due to the high security risks it poses. Starting from Liferay DXP 2024.Q2 and later, a new feature has been introduced in Instance Settings that allows administrators to configure whether Groovy scripts are allowed in their instances.

Scores

CVSS v3 7.2
EPSS 0.0054
EPSS Percentile 67.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (4)
com.liferay/com.liferay.object.service 0 - 1.0.96Maven
liferay/digital_experience_platform 7.4 update27 (16 CPE variants)
liferay/digital_experience_platform 2023.Q3.1 - 2023.Q3.10
liferay/liferay_portal 7.4.3.27 - 7.4.3.43
Published Sep 01, 2025
Tracked Since Feb 18, 2026