CVE-2022-42127
published 2022-11-15CVE-2022-42127: The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, which…
PriorityP425medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.66%
47.7th percentile
The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, which allows remote attackers to obtain the history of all friendly URLs that was assigned to a page.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | liferay_portal | >= 7.4.3.5 < 7.4.3.37 | 7.4.3.37 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Liferay Portal/DXP Friendly URL permission
vuldb·2026-07-08·CVSS 5.3
CVE-2022-42127 [MEDIUM] Liferay Portal/DXP Friendly URL permission
A vulnerability labeled as critical has been found in Liferay Portal and DXP. Impacted is an unknown function of the component Friendly URL Module. The manipulation results in permission issues.
This vulnerability is identified as CVE-2022-42127. The attack can be executed remotely. There is not any exploit available.
OSV
Incorrect Default Permissions in Liferay Portal
osv·2022-11-15
CVE-2022-42127 [MEDIUM] Incorrect Default Permissions in Liferay Portal
Incorrect Default Permissions in Liferay Portal
The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, which allows remote attackers to obtain the history of all friendly URLs that was assigned to a page.
GHSA
Incorrect Default Permissions in Liferay Portal
ghsa·2022-11-15
CVE-2022-42127 [MEDIUM] CWE-276 Incorrect Default Permissions in Liferay Portal
Incorrect Default Permissions in Liferay Portal
The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, which allows remote attackers to obtain the history of all friendly URLs that was assigned to a page.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://issues.liferay.com/browse/LPE-17607https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42127https://issues.liferay.com/browse/LPE-17607https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42127
2022-11-15
Published