CVE Vulnerabilities

CVE-2022-42131

Improper Certificate Validation

Published: Nov 15, 2022 | Modified: Nov 18, 2022
CVSS 3.x
4.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Certain Liferay products are affected by: Missing SSL Certificate Validation in the Dynamic Data Mapping modules REST data providers. This affects Liferay Portal 7.1.0 through 7.4.2 and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Digital_experience_platform Liferay 7.1 (including) 7.1 (including)
Digital_experience_platform Liferay 7.1-fix_pack_1 (including) 7.1-fix_pack_1 (including)
Digital_experience_platform Liferay 7.1-fix_pack_10 (including) 7.1-fix_pack_10 (including)
Digital_experience_platform Liferay 7.1-fix_pack_11 (including) 7.1-fix_pack_11 (including)
Digital_experience_platform Liferay 7.1-fix_pack_12 (including) 7.1-fix_pack_12 (including)
Digital_experience_platform Liferay 7.1-fix_pack_13 (including) 7.1-fix_pack_13 (including)
Digital_experience_platform Liferay 7.1-fix_pack_14 (including) 7.1-fix_pack_14 (including)
Digital_experience_platform Liferay 7.1-fix_pack_15 (including) 7.1-fix_pack_15 (including)
Digital_experience_platform Liferay 7.1-fix_pack_16 (including) 7.1-fix_pack_16 (including)
Digital_experience_platform Liferay 7.1-fix_pack_17 (including) 7.1-fix_pack_17 (including)
Digital_experience_platform Liferay 7.1-fix_pack_18 (including) 7.1-fix_pack_18 (including)
Digital_experience_platform Liferay 7.1-fix_pack_19 (including) 7.1-fix_pack_19 (including)
Digital_experience_platform Liferay 7.1-fix_pack_2 (including) 7.1-fix_pack_2 (including)
Digital_experience_platform Liferay 7.1-fix_pack_20 (including) 7.1-fix_pack_20 (including)
Digital_experience_platform Liferay 7.1-fix_pack_21 (including) 7.1-fix_pack_21 (including)
Digital_experience_platform Liferay 7.1-fix_pack_22 (including) 7.1-fix_pack_22 (including)
Digital_experience_platform Liferay 7.1-fix_pack_23 (including) 7.1-fix_pack_23 (including)
Digital_experience_platform Liferay 7.1-fix_pack_24 (including) 7.1-fix_pack_24 (including)
Digital_experience_platform Liferay 7.1-fix_pack_25 (including) 7.1-fix_pack_25 (including)
Digital_experience_platform Liferay 7.1-fix_pack_26 (including) 7.1-fix_pack_26 (including)
Digital_experience_platform Liferay 7.1-fix_pack_3 (including) 7.1-fix_pack_3 (including)
Digital_experience_platform Liferay 7.1-fix_pack_4 (including) 7.1-fix_pack_4 (including)
Digital_experience_platform Liferay 7.1-fix_pack_5 (including) 7.1-fix_pack_5 (including)
Digital_experience_platform Liferay 7.1-fix_pack_6 (including) 7.1-fix_pack_6 (including)
Digital_experience_platform Liferay 7.1-fix_pack_7 (including) 7.1-fix_pack_7 (including)
Digital_experience_platform Liferay 7.1-fix_pack_8 (including) 7.1-fix_pack_8 (including)
Digital_experience_platform Liferay 7.1-fix_pack_9 (including) 7.1-fix_pack_9 (including)
Digital_experience_platform Liferay 7.2 (including) 7.2 (including)
Digital_experience_platform Liferay 7.2-fix_pack_1 (including) 7.2-fix_pack_1 (including)
Digital_experience_platform Liferay 7.2-fix_pack_10 (including) 7.2-fix_pack_10 (including)
Digital_experience_platform Liferay 7.2-fix_pack_11 (including) 7.2-fix_pack_11 (including)
Digital_experience_platform Liferay 7.2-fix_pack_12 (including) 7.2-fix_pack_12 (including)
Digital_experience_platform Liferay 7.2-fix_pack_13 (including) 7.2-fix_pack_13 (including)
Digital_experience_platform Liferay 7.2-fix_pack_14 (including) 7.2-fix_pack_14 (including)
Digital_experience_platform Liferay 7.2-fix_pack_15 (including) 7.2-fix_pack_15 (including)
Digital_experience_platform Liferay 7.2-fix_pack_16 (including) 7.2-fix_pack_16 (including)
Digital_experience_platform Liferay 7.2-fix_pack_2 (including) 7.2-fix_pack_2 (including)
Digital_experience_platform Liferay 7.2-fix_pack_3 (including) 7.2-fix_pack_3 (including)
Digital_experience_platform Liferay 7.2-fix_pack_4 (including) 7.2-fix_pack_4 (including)
Digital_experience_platform Liferay 7.2-fix_pack_5 (including) 7.2-fix_pack_5 (including)
Digital_experience_platform Liferay 7.2-fix_pack_6 (including) 7.2-fix_pack_6 (including)
Digital_experience_platform Liferay 7.2-fix_pack_7 (including) 7.2-fix_pack_7 (including)
Digital_experience_platform Liferay 7.2-fix_pack_8 (including) 7.2-fix_pack_8 (including)
Digital_experience_platform Liferay 7.2-fix_pack_9 (including) 7.2-fix_pack_9 (including)
Digital_experience_platform Liferay 7.3 (including) 7.3 (including)
Digital_experience_platform Liferay 7.3-fix_pack_1 (including) 7.3-fix_pack_1 (including)
Digital_experience_platform Liferay 7.3-fix_pack_2 (including) 7.3-fix_pack_2 (including)
Liferay_portal Liferay 7.1.0 (including) 7.4.3.4 (excluding)

Potential Mitigations

References