CVE-2022-42132
published 2022-11-15CVE-2022-42132: The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 before fix…
PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.47%
37.5th percentile
The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before update 4, and DXP 7.4 GA includes the LDAP credential in the page URL when paginating through the list of users, which allows man-in-the-middle attackers or attackers with access to the request logs to see the LDAP credential.
Affected
151 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Liferay Portal/DXP Test LDAP User channel accessible
vuldb·2026-07-08·CVSS 5.9
CVE-2022-42132 [MEDIUM] Liferay Portal/DXP Test LDAP User channel accessible
A vulnerability was found in Liferay Portal and DXP. It has been classified as critical. This vulnerability affects unknown code of the component Test LDAP User Handler. Performing a manipulation results in channel accessible by non-endpoint.
This vulnerability is known as CVE-2022-42132. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
OSV
Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL
osv·2022-11-15
CVE-2022-42132 [MEDIUM] Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL
Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL
The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before update 4, and DXP 7.4 GA includes the LDAP credential in the page URL when paginating through the list of users, which allows man-in-the-middle attackers or attackers with access to the request logs to see the LDAP credential.
GHSA
Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL
ghsa·2022-11-15
CVE-2022-42132 [MEDIUM] CWE-200 Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL
Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL
The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before update 4, and DXP 7.4 GA includes the LDAP credential in the page URL when paginating through the list of users, which allows man-in-the-middle attackers or attackers with access to the request logs to see the LDAP credential.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://issues.liferay.com/browse/LPE-17438https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42132https://issues.liferay.com/browse/LPE-17438https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42132
2022-11-15
Published