Lucene search

K
cvelistMitreCVELIST:CVE-2022-42126
HistoryNov 15, 2022 - 12:00 a.m.

CVE-2022-42126

2022-11-1500:00:00
mitre
www.cve.org
1
liferay portal
asset libraries
permissions
remote users
authenticated
ui access

4.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.8%

The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI.

4.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.8%

Related for CVELIST:CVE-2022-42126