First published: Tue Nov 15 2022(Updated: )
The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 19, 7.3 before update 4, and 7.4 GA does not properly check permission of form entries, which allows remote authenticated users to view and access all form entries.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Liferay Digital Experience Platform | =7.1 | |
Liferay Digital Experience Platform | =7.1-fix_pack_1 | |
Liferay Digital Experience Platform | =7.1-fix_pack_10 | |
Liferay Digital Experience Platform | =7.1-fix_pack_11 | |
Liferay Digital Experience Platform | =7.1-fix_pack_12 | |
Liferay Digital Experience Platform | =7.1-fix_pack_13 | |
Liferay Digital Experience Platform | =7.1-fix_pack_14 | |
Liferay Digital Experience Platform | =7.1-fix_pack_15 | |
Liferay Digital Experience Platform | =7.1-fix_pack_16 | |
Liferay Digital Experience Platform | =7.1-fix_pack_17 | |
Liferay Digital Experience Platform | =7.1-fix_pack_18 | |
Liferay Digital Experience Platform | =7.1-fix_pack_19 | |
Liferay Digital Experience Platform | =7.1-fix_pack_2 | |
Liferay Digital Experience Platform | =7.1-fix_pack_20 | |
Liferay Digital Experience Platform | =7.1-fix_pack_21 | |
Liferay Digital Experience Platform | =7.1-fix_pack_22 | |
Liferay Digital Experience Platform | =7.1-fix_pack_23 | |
Liferay Digital Experience Platform | =7.1-fix_pack_24 | |
Liferay Digital Experience Platform | =7.1-fix_pack_25 | |
Liferay Digital Experience Platform | =7.1-fix_pack_26 | |
Liferay Digital Experience Platform | =7.1-fix_pack_3 | |
Liferay Digital Experience Platform | =7.1-fix_pack_4 | |
Liferay Digital Experience Platform | =7.1-fix_pack_5 | |
Liferay Digital Experience Platform | =7.1-fix_pack_6 | |
Liferay Digital Experience Platform | =7.1-fix_pack_7 | |
Liferay Digital Experience Platform | =7.1-fix_pack_8 | |
Liferay Digital Experience Platform | =7.1-fix_pack_9 | |
Liferay Digital Experience Platform | =7.2 | |
Liferay Digital Experience Platform | =7.2-fix_pack_1 | |
Liferay Digital Experience Platform | =7.2-fix_pack_10 | |
Liferay Digital Experience Platform | =7.2-fix_pack_11 | |
Liferay Digital Experience Platform | =7.2-fix_pack_12 | |
Liferay Digital Experience Platform | =7.2-fix_pack_13 | |
Liferay Digital Experience Platform | =7.2-fix_pack_14 | |
Liferay Digital Experience Platform | =7.2-fix_pack_15 | |
Liferay Digital Experience Platform | =7.2-fix_pack_16 | |
Liferay Digital Experience Platform | =7.2-fix_pack_2 | |
Liferay Digital Experience Platform | =7.2-fix_pack_3 | |
Liferay Digital Experience Platform | =7.2-fix_pack_4 | |
Liferay Digital Experience Platform | =7.2-fix_pack_5 | |
Liferay Digital Experience Platform | =7.2-fix_pack_6 | |
Liferay Digital Experience Platform | =7.2-fix_pack_7 | |
Liferay Digital Experience Platform | =7.2-fix_pack_8 | |
Liferay Digital Experience Platform | =7.2-fix_pack_9 | |
Liferay Digital Experience Platform | =7.3 | |
Liferay Digital Experience Platform | =7.4 | |
Liferay Liferay Portal | >=7.1.0<7.4.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42130 is a vulnerability in the Dynamic Data Mapping module in Liferay Portal and Liferay DXP, which allows remote authenticated users to view and access all form entries.
The severity of CVE-2022-42130 is medium with a CVSS score of 4.3.
CVE-2022-42130 affects Liferay Portal versions 7.1.0 through 7.4.3.4 and Liferay DXP versions 7.1 before fix pack 27, 7.2 before fix pack 19, 7.3 before update 4, and 7.4 GA.
Remote authenticated users can exploit CVE-2022-42130 by viewing and accessing all form entries, compromising the confidentiality and integrity of the data.
Yes, fixes are available for CVE-2022-42130. It is recommended to update to the latest version of Liferay Portal or Liferay DXP that includes the fix.