First published: Tue Nov 15 2022(Updated: )
An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form entries via the `formInstanceRecordId` parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Liferay Digital Experience Platform | =7.3 | |
Liferay Digital Experience Platform | =7.4 | |
Liferay Liferay Portal | >=7.3.2<7.4.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-42129 is medium.
CVE-2022-42129 affects Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4 and 7.4 GA.
An Insecure Direct Object Reference (IDOR) vulnerability allows unauthorized access to restricted resources by manipulating object references.
A remote authenticated user can exploit CVE-2022-42129 by viewing and accessing form entries using the 'formInstanceRecordId' parameter.
Yes, Liferay Portal 7.4.3.5 and later versions contain the fix for CVE-2022-42129.