Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.19 exposes Internal Server Error in the response body when a login attempt is made with a deleted Client Secret.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Digital_experience_platform | Liferay | 2024.q1.1 (including) | 2024.q1.20 (excluding) |
| Digital_experience_platform | Liferay | 2024.q2.0 (including) | 2024.q2.13 (including) |
| Digital_experience_platform | Liferay | 2024.Q3.0 (including) | 2024.Q3.13 (including) |
| Digital_experience_platform | Liferay | 2024.q4.0 (including) | 2024.q4.7 (including) |
| Digital_experience_platform | Liferay | 2025.Q1.0 (including) | 2025.Q1.17 (excluding) |
| Digital_experience_platform | Liferay | 2025.Q2.0 (including) | 2025.Q2.10 (excluding) |
| Liferay_portal | Liferay | 7.4.0 (including) | 7.4.3.132 (including) |