Liferay Portal and DXP does not properly expire sessions
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Sep 24, 2025 
          to the GitHub Advisory Database
          •
          Updated Sep 27, 2025 
      
  
Package
Affected versions
< 5.0.51
  Patched versions
5.0.51
  Description
        Published by the National Vulnerability Database
      Sep 24, 2025 
    
  
        Published to the GitHub Advisory Database
      Sep 24, 2025 
    
  
        Reviewed
      Sep 24, 2025 
    
  
        Last updated
      Sep 27, 2025 
    
  
Summary
Liferay Portal/DXP contains an Insufficient Session Expiration issue where the Single Logout (SLO) API may fail to invalidate a user’s previous session. An attacker can reuse a stale session via the SLO endpoint to gain an authenticated context.
Affected Versions
The following platform versions are affected:
7.3.3.131through7.4.3.1212024.Q4.0–2024.Q4.32024.Q3.1–2024.Q3.132024.Q2.0–2024.Q2.132024.Q1.1–2024.Q1.12Remediation
Update to the fixed builds and, for Maven consumers of the SAML module, upgrade
com.liferay:com.liferay.saml.implto 5.0.51 or later. After upgrading, ensure session invalidation policies are enforced and verify SLO behavior end-to-end.References