CVE-2022-28981: Path Traversal
Path traversal vulnerability in the Hypermedia REST APIs module before 4.0.12 from Liferay Portal (7.4.0 through 7.4.2) allows remote attackers to access files outside of com.liferay.headless.discovery.web/META-INF/resources via the parameter parameter.
Other sources
Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote attackers to access files outside of com.liferay.headless.discovery.web/META-INF/resources via the parameter parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay:com.liferay.headless.discovery.webto a version that resolves this vulnerability.Fixed in 4.0.12
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28981?
CVE-2022-28981 is classified as a medium severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2022-28981?
To mitigate CVE-2022-28981, upgrade Liferay Portal to a version later than 7.4.2.
What are the potential impacts of CVE-2022-28981?
The potential impact of CVE-2022-28981 includes unauthorized access to sensitive files on the server.
Which versions of Liferay are affected by CVE-2022-28981?
Liferay Portal versions 7.4.0 through 7.4.2 are affected by CVE-2022-28981.
What type of attack does CVE-2022-28981 enable?
CVE-2022-28981 enables path traversal attacks, allowing remote attackers to access restricted file directories.