CVE-2022-42129: Medium severity Liferay Digital Experience Platform vulnerability
An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form entries via the formInstanceRecordId parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-42129?
The severity of CVE-2022-42129 is medium.
How does CVE-2022-42129 affect Liferay Portal and Liferay DXP?
CVE-2022-42129 affects Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4 and 7.4 GA.
What is an Insecure Direct Object Reference (IDOR) vulnerability?
An Insecure Direct Object Reference (IDOR) vulnerability allows unauthorized access to restricted resources by manipulating object references.
How can a remote authenticated user exploit CVE-2022-42129?
A remote authenticated user can exploit CVE-2022-42129 by viewing and accessing form entries using the 'formInstanceRecordId' parameter.
Are there any known fixes or updates for CVE-2022-42129?
Yes, Liferay Portal 7.4.3.5 and later versions contain the fix for CVE-2022-42129.