PT-2022-19341 · Liferay · Liferay Portal

Published

2022-09-22

·

Updated

2022-09-23

·

CVE-2022-28981

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.4.0 through 7.4.2
Description A path traversal issue in the Hypermedia REST APIs module allows remote attackers to access files outside of the intended directory via the parameter parameter. This could potentially lead to unauthorized access to sensitive information.
Recommendations For Liferay Portal versions 7.4.0 through 7.4.2, consider restricting access to the Hypermedia REST APIs module until a patch is available. As a temporary workaround, avoid using the parameter parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-28981
GHSA-5J86-VMPX-42PC

Affected Products

Liferay Portal