CVE-2022-42131: Medium severity Liferay Digital Experience Platform vulnerability
Certain Liferay products are affected by: Missing SSL Certificate Validation in the Dynamic Data Mapping module's REST data providers. This affects Liferay Portal 7.1.0 through 7.4.2 and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Liferay Portalto a version that resolves this vulnerability.Patch 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3 - Upgrade
Upgrade
Liferay DXP 7.1to a version that resolves this vulnerability.Patch before fix pack 27
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2022-42131.
Which products are affected by CVE-2022-42131?
Certain Liferay products are affected, including Liferay Portal 7.1.0 through 7.4.2 and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3.
What is the severity rating of CVE-2022-42131?
The severity rating of CVE-2022-42131 is 4.8 (medium).
What is the CWE ID of CVE-2022-42131?
The CWE ID of CVE-2022-42131 is 295.
How can I fix CVE-2022-42131?
To fix CVE-2022-42131, it is recommended to update to the latest version of Liferay Portal or Liferay DXP that includes the necessary fixes.