Lucene search

K
cve[email protected]CVE-2022-42126
HistoryNov 15, 2022 - 1:15 a.m.

CVE-2022-42126

2022-11-1501:15:13
web.nvd.nist.gov
35
7
cve-2022-42126
asset libraries
liferay portal
liferay dxp
permissions
remote authentication
security vulnerability

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

4.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.8%

The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI.

Affected configurations

NVD
Node
liferaydigital_experience_platformMatch7.3-
OR
liferaydigital_experience_platformMatch7.4-
OR
liferaydigital_experience_platformMatch7.4update1
OR
liferayliferay_portalRange7.3.57.4.3.29

Social References

More

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

4.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.8%

Related for CVE-2022-42126