CVE-2022-42123: Path Traversal
A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-42123?
The severity of CVE-2022-42123 is high with a value of 7.5.
Which software versions are affected by CVE-2022-42123?
CVE-2022-42123 affects Liferay Digital Experience Platform versions 7.3 and 7.4, and Liferay Portal versions 7.3.3 to 7.4.3.18.
How does CVE-2022-42123 allow attackers to compromise the system?
CVE-2022-42123 allows attackers to create or overwrite existing files on the filesystem through the installation of a malicious Elasticsearch Sidecar plugin.
Is there a fix available for CVE-2022-42123?
Yes, the fix for CVE-2022-42123 is to update Liferay Digital Experience Platform to version 7.3 update 6 or 7.4 update 19, and Liferay Portal to version 7.4.3.19.
Where can I find more information about CVE-2022-42123?
More information about CVE-2022-42123 can be found at the following references: [http://liferay.com](http://liferay.com), [https://issues.liferay.com/browse/LPE-17518](https://issues.liferay.com/browse/LPE-17518), [https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42123](https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42123).