CVE-2022-39975: Medium severity Liferay DXP vulnerability
The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the preview of a "Content Page" type page, allowing attackers to view unpublished "Content Page" pages via URL manipulation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Liferay Portal/Layout module / Content Page previewto a version that resolves this vulnerability.Fixed in 7.4.3.34
Event History
Frequently Asked Questions
What is the vulnerability ID for this Liferay Portal and DXP vulnerability?
The vulnerability ID for this Liferay Portal and DXP vulnerability is CVE-2022-39975.
What is the severity of CVE-2022-39975?
The severity of CVE-2022-39975 is medium with a CVSS score of 4.3.
Which versions of Liferay Portal and DXP are affected by CVE-2022-39975?
CVE-2022-39975 affects Liferay Portal versions 7.3.3 through 7.4.3.34 and Liferay DXP versions 7.3 before update 10 and 7.4 before update 35.
What is the impact of CVE-2022-39975?
CVE-2022-39975 allows attackers to view unpublished "Content Page" pages in Liferay Portal and DXP via URL manipulation.
Are there any fixes or patches available for CVE-2022-39975?
Yes, updates and fixes are available for CVE-2022-39975. Please refer to the official Liferay website for more information.