CVE-2022-42123
published 2022-11-15CVE-2022-42123: A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.70%
49.2th percentile
A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | liferay_portal | >= 7.3.3 < 7.4.3.19 | 7.4.3.19 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Liferay Portal/DXP Elasticsearch Connector path traversal
vuldb·2026-07-07·CVSS 7.5
CVE-2022-42123 [HIGH] Liferay Portal/DXP Elasticsearch Connector path traversal
A vulnerability classified as problematic has been found in Liferay Portal and DXP. Affected by this vulnerability is an unknown functionality of the component Elasticsearch Connector. The manipulation leads to path traversal.
This vulnerability is listed as CVE-2022-42123. The attack must be carried out from within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
GHSA
Path Traversal in Liferay Portal
ghsa·2022-11-15
CVE-2022-42123 [HIGH] CWE-22 Path Traversal in Liferay Portal
Path Traversal in Liferay Portal
A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.
OSV
Path Traversal in Liferay Portal
osv·2022-11-15
CVE-2022-42123 [HIGH] Path Traversal in Liferay Portal
Path Traversal in Liferay Portal
A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://issues.liferay.com/browse/LPE-17518https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42123https://issues.liferay.com/browse/LPE-17518https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42123
2022-11-15
Published