CVE-2022-42127: Medium severity Liferay Digital Experience Platform vulnerability
The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, which allows remote attackers to obtain the history of all friendly URLs that was assigned to a page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.48
Event History
Frequently Asked Questions
What is the severity of CVE-2022-42127?
The severity of CVE-2022-42127 is medium with a CVSS score of 5.3.
Which software versions are affected by CVE-2022-42127?
CVE-2022-42127 affects Liferay Portal versions 7.4.3.5 through 7.4.3.36 and Liferay DXP versions 7.4 update 1 through 36.
How can remote attackers exploit CVE-2022-42127?
Remote attackers can exploit CVE-2022-42127 to obtain the history of all friendly URLs assigned to a page.
Are there any known fixes for CVE-2022-42127?
At the moment, there are no known fixes available for CVE-2022-42127. It is recommended to stay updated with the latest security information from Liferay.
Where can I find more information about CVE-2022-42127?
You can find more information about CVE-2022-42127 on the Liferay website, the Liferay issue tracker, and the Liferay security known vulnerabilities page.