CVE-2022-42128: Medium severity Liferay Digital Experience Platform vulnerability
The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows remote attackers to obtain a WikiNode object via the WikiNodeResource.getSiteWikiNodeByExternalReferenceCode API.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-42128?
The severity of CVE-2022-42128 is medium with a severity value of 5.3.
How does CVE-2022-42128 affect Liferay Digital Experience Platform?
CVE-2022-42128 affects Liferay Digital Experience Platform version 7.4.
How does CVE-2022-42128 affect Liferay Portal?
CVE-2022-42128 affects Liferay Portal versions 7.4.1 through 7.4.3.4.
What is the vulnerability description for CVE-2022-42128?
CVE-2022-42128 is a vulnerability in the Hypermedia REST APIs module in Liferay Portal and Liferay DXP that allows remote attackers to obtain a WikiNode object via the WikiNodeResource.getSiteWikiNodeByExternalReferenceCode API.
Are there any references for CVE-2022-42128?
Yes, you can find references for CVE-2022-42128 on the Liferay website, the Liferay issue tracker, and the Liferay security vulnerabilities page.