Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. com.liferay/com.liferay.multi.factor.authentication.timebased.otp.web
  4. ›
  5. CVE-2025-43798

CVE-2025-43798: Liferay DXP Missing Critical Step in Authentication

September 15, 2025 (updated November 10, 2025)

Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TOTP) to be used multiple times during the validity period, which allows attackers with access to a user’s TOTP to authenticate as the user.

References

  • github.com/advisories/GHSA-4p5r-3jmm-652q
  • github.com/liferay/liferay-portal
  • github.com/liferay/liferay-portal/commit/1df25e46675afe7c3a2754bf8968bcb9677db950
  • liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-43798
  • nvd.nist.gov/vuln/detail/CVE-2025-43798

Code Behaviors & Features

Detect and mitigate CVE-2025-43798 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.0.25

Fixed versions

  • 2.0.25

Solution

Upgrade to version 2.0.25 or above.

Impact 3.1 LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-304: Missing Critical Step in Authentication

Source file

maven/com.liferay/com.liferay.multi.factor.authentication.timebased.otp.web/CVE-2025-43798.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 04 Feb 2026 00:36:09 +0000.