CVE-2022-42124: High severity Liferay Digital Experience Platform vulnerability
ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.2 fix pack 9 through fix pack 18, 7.3 before update 4, and DXP 7.4 GA allows remote attackers to consume an excessive amount of server resources via a crafted payload injected into the 'name' field of a layout prototype.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.5 - Upgrade
Upgrade
Liferay Portalto a version that resolves this vulnerability.Fixed in 7.3.2 through 7.4.3.4 - Upgrade
Upgrade
Liferay DXPto a version that resolves this vulnerability.Fixed in 7.2 fix pack 9 through fix pack 18, 7.3 before update 4, and DXP 7.4 GA
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-42124.
What is the severity of CVE-2022-42124?
The severity of CVE-2022-42124 is high with a severity value of 7.5.
Which software versions are affected by CVE-2022-42124?
CVE-2022-42124 affects Liferay Portal versions 7.3.2 through 7.4.3.4 and Liferay DXP versions 7.2 fix pack 9 through fix pack 18, 7.3 before update 4, and DXP 7.4 GA.
How can a remote attacker exploit CVE-2022-42124?
A remote attacker can exploit CVE-2022-42124 by injecting a crafted payload into Liferay Portal, consuming an excessive amount of server resources.
How can I fix CVE-2022-42124?
To fix CVE-2022-42124, update to Liferay Portal version 7.4.3.5 or higher.