PT-2022-26274 · Liferay · Liferay Portal+1

Published

2022-11-15

·

Updated

2025-04-30

·

CVE-2022-42128

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.4.1 through 7.4.3.4 Liferay DXP version 7.4 GA
Description The issue concerns the Hypermedia REST APIs module, which fails to properly check permissions. This allows remote attackers to obtain a WikiNode object via the "WikiNodeResource.getSiteWikiNodeByExternalReferenceCode" API endpoint, using the externalReferenceCode variable.
Recommendations For Liferay Portal versions 7.4.1 through 7.4.3.4, consider restricting access to the WikiNodeResource API endpoint until a patch is available. For Liferay DXP version 7.4 GA, restrict access to the WikiNodeResource API endpoint until a patch is available. As a temporary workaround, consider disabling the WikiNodeResource.getSiteWikiNodeByExternalReferenceCode API endpoint until a patch is available.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BIT-LIFERAY-2022-42128
CVE-2022-42128
GHSA-WGQM-QP44-CG6X

Affected Products

Liferay Dxp
Liferay Portal