CVE-2022-42123Path Traversal in Portal

CWE-22Path Traversal4 documents4 sources
Severity
7.5HIGHNVD
EPSS
0.4%
top 38.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15

Description

A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDliferay/liferay_portal7.3.37.4.3.19

🔴Vulnerability Details

3
GHSA
Path Traversal in Liferay Portal2022-11-15
OSV
Path Traversal in Liferay Portal2022-11-15
CVEList
CVE-2022-42123: A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 72022-11-15
CVE-2022-42123 — Path Traversal in Liferay Portal | cvebase