Liferay Portal, Open Redirection, CVE-2025-21669 (Moderate)

Listen to this Post

The CVE-2025-21669 vulnerability in Liferay Portal is a DNS rebinding attack leading to open redirection. By default, the portal’s redirect mechanism validates the target URL based on the resolved IP address. An attacker can exploit this by registering a domain name that initially resolves to an allowed, whitelisted IP address. After the user’s browser resolves the domain, the attacker re-binds the DNS record to a malicious IP. When Liferay subsequently triggers a redirect to this domain, it checks the now-malicious IP but may still allow the redirect if the original domain is in a permitted list or due to a race condition, successfully sending the user to an attacker-controlled site. This bypasses the intended IP-based validation.
Platform: Liferay Portal/DXP
Version: 7.4.0 – 7.4.3.119
Vulnerability: Open Redirection
Severity: Moderate
date: 2024-10-30

Prediction: 2024-11-15

What Undercode Say:

nslookup attacker-controlled.domain
dig +short A attacker-controlled.domain
// Simulate redirect logic
if (isWhitelisted(resolvedIP)) {
window.location = userSuppliedURL;
}

How Exploit:

Attacker registers domain.

Domain resolves to allowed IP.

User visits Liferay page.

Redirect triggered to domain.

DNS rebinds to malicious IP.

User redirected to attacker site.

Protection from this CVE

Update to version 7.4.3.110.

Configure redirect URL security.

Use domain whitelisting, not IP.

Implement strict CORS policies.

Impact:

User redirection to phishing.

Session theft potential.

Client-side attacks.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top