Access Control Vulnerability in Liferay Portal Dynamic Data Mapping Module
CVE-2022-42130

4.3MEDIUM

Key Information:

Vendor

Liferay

Vendor
CVE Published:
15 November 2022

What is CVE-2022-42130?

The Dynamic Data Mapping module within Liferay Portal fails to appropriately enforce permissions on form entries. This oversight permits remote authenticated users to gain unauthorized access to sensitive form data, which could lead to data leakage or misuse. Affected versions include Liferay Portal 7.1.0 to 7.4.3.4 and various fix packs of Liferay DXP. It is critical for users to evaluate their installations and apply the recommended patches to mitigate this risk.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.