Zip Slip Vulnerability in Liferay Portal and DXP by Liferay
CVE-2022-42123
7.5HIGH
Key Information:
- Vendor
Liferay
- Vendor
- CVE Published:
- 15 November 2022
What is CVE-2022-42123?
The Zip Slip vulnerability in the Elasticsearch Connector of Liferay Portal and DXP allows attackers to exploit specific versions of these products. By installing a malicious Elasticsearch Sidecar plugin, an attacker can create or overwrite existing files on the underlying filesystem, posing a significant risk to the integrity of data and system configurations. This flaw affects users of Liferay Portal from versions 7.3.3 through 7.4.3.18 and Liferay DXP before certain updates. It is imperative for users to review their version and apply the necessary patches to mitigate the risks.