First published: Tue Nov 15 2022(Updated: )
The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Liferay DXP | =7.3 | |
Liferay DXP | =7.4 | |
Liferay DXP | =7.4-update1 | |
Liferay 7.4 GA | >=7.3.5<7.4.3.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-42126.
The severity level of CVE-2022-42126 is medium with a severity value of 4.3.
CVE-2022-42126 affects Liferay Portal versions 7.3.5 through 7.4.3.28, Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29.
CVE-2022-42126 allows remote authenticated users to view asset libraries via the UI.
Yes, you can find references for CVE-2022-42126 on the following links: [Liferay](http://liferay.com), [Liferay Issue Tracker](https://issues.liferay.com/browse/LPE-17593), [Liferay Security Advisories](https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42126).