<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>Is the latest released Portal Docker image vulnerable to CVE-2025-24813?</title>
  <link rel="self" href="https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=123318726" />
  <subtitle>Is the latest released Portal Docker image vulnerable to CVE-2025-24813?</subtitle>
  <id>https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=123318726</id>
  <updated>2026-04-07T23:24:30Z</updated>
  <dc:date>2026-04-07T23:24:30Z</dc:date>
  <entry>
    <title>RE: Is the latest released Portal Docker image vulnerable to CVE-2025-24813?</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=123367682" />
    <author>
      <name>Daniel Carrillo Broeder</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=123367682</id>
    <updated>2025-04-23T10:14:39Z</updated>
    <published>2025-04-23T10:14:38Z</published>
    <summary type="html">&lt;p&gt;Liferay is &lt;strong&gt;not vulnerable&lt;/strong&gt; with its bundle/docker
  image default configuration( &lt;a
    href="https://help.liferay.com/hc/en-us/articles/35134053445517-Liferay-and-CVE-2025-24813"&gt;Liferay
    and CVE-2025-24813&lt;/a&gt; ). Also, the Tomcat version will be updated
  the future.&lt;/p&gt;
&lt;p&gt;You can create a temporary container if you want to verify the
  specific Tomcat version of a tag:&lt;/p&gt;
&lt;pre&gt;
&lt;code class="language-java"&gt;docker run -it -entrypoint /bin/bash --name test liferay/portal:7.4.3.132-ga132

$ java -cp /opt/liferay/tomcat/lib/catalina.jar org.apache.catalina.util.ServerInfo
Server version: Apache Tomcat/9.0.98
...&lt;/code&gt;&lt;/pre&gt;</summary>
    <dc:creator>Daniel Carrillo Broeder</dc:creator>
    <dc:date>2025-04-23T10:14:38Z</dc:date>
  </entry>
  <entry>
    <title>Is the latest released Portal Docker image vulnerable to CVE-2025-24813?</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=123318725" />
    <author>
      <name>Effi S.</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=123318725</id>
    <updated>2025-03-26T15:35:59Z</updated>
    <published>2025-03-25T19:22:55Z</published>
    <summary type="html">&lt;p&gt;Hey everyone,&lt;/p&gt;
&lt;p&gt;I am currently running the Liferay Portal image locally for a PoC but
  since patching would be an issue in a production environment I am
  curious about the support structure here.&lt;/p&gt;
&lt;p&gt;Does anyone know if the latest released Docker image
  (https://hub.docker.com/r/liferay/portal/tags) is vulnerable to CVE-2025-24813?&lt;/p&gt;
&lt;p&gt;And if so, is there any pattern to how new Docker images with patches
  are published? Like how many weeks does it usually take etc.?&lt;/p&gt;
&lt;p&gt;Or is there any sort of workaround where one could override the
  tomcat version in some way?&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;</summary>
    <dc:creator>Effi S.</dc:creator>
    <dc:date>2025-03-25T19:22:55Z</dc:date>
  </entry>
</feed>
