CVE-2022-28977: Medium severity Liferay DXP vulnerability
HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack 5 through 14, and 7.3 before service pack 3 can be circumvented by using multiple forward slashes, which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect parameter (2) FORWARDURL parameter, and (3) others parameters that rely on HtmlUtil.escapeRedirect.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:com.liferay.util.javato a version that resolves this vulnerability.Fixed in 7.9.0 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp14 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.1.10.fp25 - Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.0.10.fp101 - Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.4-ga4 - Upgrade
Upgrade
Liferay Portalto a version that resolves this vulnerability.Fixed in 7.3.1
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-28977.
What is the severity level of CVE-2022-28977?
CVE-2022-28977 has a severity level of 6.1 (medium).
Which software versions are affected by CVE-2022-28977?
CVE-2022-28977 affects Liferay Portal versions 7.3.1 through 7.4.2 and Liferay DXP versions 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack 5 through 14, and 7.3 before service pack 3.
How can the vulnerability be exploited?
The vulnerability can be exploited by using multiple forward slashes to bypass HtmlUtil.escapeRedirect in Liferay Portal and Liferay DXP, which allows remote attackers to redirect users to malicious websites.
Where can I find more information about CVE-2022-28977?
More information about CVE-2022-28977 can be found at the official Liferay website and the Liferay Developer Portal.