CVE-2022-42128
published 2022-11-15CVE-2022-42128: The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows remote…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.66%
47.7th percentile
The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows remote attackers to obtain a WikiNode object via the WikiNodeResource.getSiteWikiNodeByExternalReferenceCode API.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | digital_experience_platform | — | — |
| liferay | liferay_portal | >= 7.4.1 < 7.4.3.5 | 7.4.3.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Liferay Portal/DXP Hypermedia REST API permission
vuldb·2026-07-08·CVSS 5.3
CVE-2022-42128 [MEDIUM] Liferay Portal/DXP Hypermedia REST API permission
A vulnerability, which was classified as critical, was found in Liferay Portal and DXP. This affects an unknown function of the component Hypermedia REST API. Executing a manipulation can lead to permission issues.
This vulnerability appears as CVE-2022-42128. The attack may be performed from remote. There is no available exploit.
OSV
Incorrect Default Permissions in Liferay Portal
osv·2022-11-15
CVE-2022-42128 [MEDIUM] Incorrect Default Permissions in Liferay Portal
Incorrect Default Permissions in Liferay Portal
The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows remote attackers to obtain a WikiNode object via the WikiNodeResource.getSiteWikiNodeByExternalReferenceCode API.
GHSA
Incorrect Default Permissions in Liferay Portal
ghsa·2022-11-15
CVE-2022-42128 [MEDIUM] CWE-276 Incorrect Default Permissions in Liferay Portal
Incorrect Default Permissions in Liferay Portal
The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows remote attackers to obtain a WikiNode object via the WikiNodeResource.getSiteWikiNodeByExternalReferenceCode API.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://issues.liferay.com/browse/LPE-17595https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42128https://issues.liferay.com/browse/LPE-17595https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42128
2022-11-15
Published