CVE-2022-26595: Medium severity Liferay Digital Experience Platform vulnerability
Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the user's site membership assignment UI.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:com.liferay.portal.implto a version that resolves this vulnerability.Fixed in 7.7.9 - Upgrade
Upgrade
maven/com.liferay:com.liferay.site.browser.webto a version that resolves this vulnerability.Fixed in 6.0.5 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.3.10.fp2 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp13 - Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.2-ga3 - Upgrade
Upgrade
Liferay Portal 7.3.7to a version that resolves this vulnerability.Fixed in 7.3 fix pack 2 - Upgrade
Upgrade
Liferay DXP 7.2to a version that resolves this vulnerability.Fixed in fix pack 13
Event History
Frequently Asked Questions
What is CVE-2022-26595?
CVE-2022-26595 is a vulnerability in Liferay Portal and Liferay DXP that allows remote authenticated users to view sites/groups via the user's site membership assignment UI.
What is the severity of CVE-2022-26595?
CVE-2022-26595 has a severity rating of medium (4.3).
Which software versions are affected by CVE-2022-26595?
Liferay Portal versions 7.3.7, 7.4.0, and 7.4.1, as well as Liferay DXP versions 7.2 fix pack 13 and 7.3 fix pack 2 are affected by CVE-2022-26595.
How can remote authenticated users exploit CVE-2022-26595?
Remote authenticated users can exploit CVE-2022-26595 by accessing a list of sites/groups via the user's site membership assignment UI.
Is there a fix available for CVE-2022-26595?
Yes, a fix is available. Please refer to the official Liferay Portal documentation and security advisories for more information on how to apply the fix.