ReDoS Vulnerability in Liferay Portal and Liferay DXP
CVE-2022-42124
7.5HIGH
Key Information:
- Vendor
Liferay
- Vendor
- CVE Published:
- 15 November 2022
What is CVE-2022-42124?
This vulnerability affects the LayoutPageTemplateEntryUpgradeProcess in Liferay Portal and Liferay DXP, allowing remote attackers to exploit the malformed 'name' field within layout prototypes. By sending a specifically crafted payload, attackers can cause excessive consumption of server resources, potentially leading to degraded performance or denial of service. Proper sanitization and input validation are essential to mitigate this risk and protect server integrity.