CVE-2022-42114: XSS
A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML.
Other sources
A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Roles Admin Web before 5.0.48 from Liferay Portal (7.4.0 through 7.4.3.36), and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.4.13.u37 - Upgrade
Upgrade
maven/com.liferay:com.liferay.roles.admin.webto a version that resolves this vulnerability.Fixed in 5.0.48 - Upgrade
Upgrade
Liferay Portal 7.4 (Role module / Liferay DXP 7.4)to a version that resolves this vulnerability.Fixed in update 37 - Upgrade
Upgrade
Liferay Roles Admin Webto a version that resolves this vulnerability.Fixed in 5.0.48
Event History
Frequently Asked Questions
What is CVE-2022-42114?
CVE-2022-42114 is a Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37.
How does CVE-2022-42114 affect Liferay DXP?
CVE-2022-42114 affects Liferay DXP versions 7.4.0 through 7.4.3.36 before update 37.
What is the severity of CVE-2022-42114?
The severity of CVE-2022-42114 is medium with a CVSS score of 5.4.
How can remote attackers exploit CVE-2022-42114?
Remote attackers can exploit CVE-2022-42114 by injecting arbitrary web script or HTML through the Role module's edit role assignees page.
Are there any known fixes for CVE-2022-42114?
Yes, the fix for CVE-2022-42114 is to update Liferay Portal or Liferay DXP to version 7.4.3.37 or apply the appropriate security patch.