CVE-2022-42131Improper Certificate Validation in Portal

Severity
4.8MEDIUMNVD
EPSS
0.1%
top 67.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15

Description

Certain Liferay products are affected by: Missing SSL Certificate Validation in the Dynamic Data Mapping module's REST data providers. This affects Liferay Portal 7.1.0 through 7.4.2 and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 2.2 | Impact: 2.5

Affected Packages2 packages

NVDliferay/liferay_portal7.1.07.4.3.4

🔴Vulnerability Details

3
OSV
Improper Certificate Validation in Liferay Portal2022-11-15
CVEList
CVE-2022-42131: Certain Liferay products are affected by: Missing SSL Certificate Validation in the Dynamic Data Mapping module's REST data providers2022-11-15
GHSA
Improper Certificate Validation in Liferay Portal2022-11-15
CVE-2022-42131 — Improper Certificate Validation | cvebase