CVE Vulnerabilities

CVE-2022-42126

Published: Nov 15, 2022 | Modified: Nov 18, 2022
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI.

Affected Software

Name Vendor Start Version End Version
Digital_experience_platform Liferay 7.3 (including) 7.3 (including)
Digital_experience_platform Liferay 7.4 (including) 7.4 (including)
Digital_experience_platform Liferay 7.4-update1 (including) 7.4-update1 (including)
Liferay_portal Liferay 7.3.5 (including) 7.4.3.29 (excluding)

References