Zip Slip Vulnerability in Liferay Portal and DXP by Liferay
CVE-2022-42123

7.5HIGH

Key Information:

Vendor

Liferay

Vendor
CVE Published:
15 November 2022

What is CVE-2022-42123?

The Zip Slip vulnerability in the Elasticsearch Connector of Liferay Portal and DXP allows attackers to exploit specific versions of these products. By installing a malicious Elasticsearch Sidecar plugin, an attacker can create or overwrite existing files on the underlying filesystem, posing a significant risk to the integrity of data and system configurations. This flaw affects users of Liferay Portal from versions 7.3.3 through 7.4.3.18 and Liferay DXP before certain updates. It is imperative for users to review their version and apply the necessary patches to mitigate the risks.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.