PT-2022-19339 · Liferay · Liferay Portal +1
Published
2022-09-21
·
Updated
2025-05-27
·
CVE-2022-28979
6.1
Medium
Base vector | Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Liferay Portal versions 7.1.0 through 7.4.2
Liferay DXP 7.1 before fix pack 26
Liferay DXP 7.2 before fix pack 15
Liferay DXP 7.3 before service pack 3
Description:
A cross-site scripting (XSS) issue was discovered in the Portal Search module's Custom Facet widget. This issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the `Custom Parameter Name` text field.
Recommendations:
For Liferay Portal versions 7.1.0 through 7.4.2, update to a version that includes the fix for this issue.
For Liferay DXP 7.1, apply fix pack 26 or later.
For Liferay DXP 7.2, apply fix pack 15 or later.
For Liferay DXP 7.3, apply service pack 3 or later.
As a temporary workaround, consider restricting access to the Custom Facet widget in the Portal Search module until a patch is available.
Fix
XSS
Weakness Enumeration
Related Identifiers
Affected Products
References · 12
- https://osv.dev/vulnerability/GHSA-7r3w-wggm-pjwf · Vendor Advisory
- https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-28979-xss-in-custom-facet-widget · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-28979 · Security Note
- https://issues.liferay.com/browse/LPE-17381 · Vendor Advisory
- https://github.com/liferay/liferay-portal⭐ 2171 🔗 3693 · Note
- https://github.com/liferay/liferay-portal/commit/e18065248673c77927f4839439aa200bfb965ced⭐ 2159 🔗 3687 · Note
- https://t.me/cvenotify/123742 · Telegram Post
- https://t.me/cvenotify/36648 · Telegram Post
- https://t.me/cibsecurity/50248 · Telegram Post
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28979 · Note
- http://liferay.com · Note
- https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2022-28979-xss-in-custom-facet-widget?p_r_p_assetEntryId=121612377&_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_redirect=https%3A%2F%2Fliferay.dev%3A443%2Fportal%2Fsecurity%2Fknown-vulnerabilities%3Fp_p_id%3Dcom_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt%26p_p_lifecycle%3D0%26p_p_state%3Dnormal%26p_p_mode%3Dview%26p_r_p_assetEntryId%3D121612377%26_com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet_INSTANCE_jekt_cur%3D0%26p_r_p_resetCur%3Dfalse · Note