CVE-2022-42125
published 2022-11-15CVE-2022-42125: Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers to create…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.70%
49.2th percentile
Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers to create or overwrite existing files on the filesystem via the deployment of a malicious plugin/module.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | liferay_portal | >= 7.4.3.5 < 7.4.3.36 | 7.4.3.36 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Liferay Portal/DXP ZIP File FileUtil.unzip path traversal
vuldb·2026-07-07·CVSS 7.5
CVE-2022-42125 [HIGH] Liferay Portal/DXP ZIP File FileUtil.unzip path traversal
A vulnerability classified as critical was found in Liferay Portal and DXP. Affected by this issue is the function FileUtil.unzip of the component ZIP File Handler. The manipulation results in path traversal.
This vulnerability is cataloged as CVE-2022-42125. The attack must originate from the local network. There is no exploit available.
GHSA
Path Traversal in Liferay Portal
ghsa·2022-11-15
CVE-2022-42125 [HIGH] CWE-22 Path Traversal in Liferay Portal
Path Traversal in Liferay Portal
Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers to create or overwrite existing files on the filesystem via the deployment of a malicious plugin/module.
OSV
Path Traversal in Liferay Portal
osv·2022-11-15
CVE-2022-42125 [HIGH] Path Traversal in Liferay Portal
Path Traversal in Liferay Portal
Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers to create or overwrite existing files on the filesystem via the deployment of a malicious plugin/module.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://issues.liferay.com/browse/LPE-17517https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42125https://issues.liferay.com/browse/LPE-17517https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42125
2022-11-15
Published