PT-2022-26274 · Liferay · Liferay Portal+1
Published
2022-11-15
·
Updated
2025-04-30
·
CVE-2022-42128
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Liferay Portal versions 7.4.1 through 7.4.3.4
Liferay DXP version 7.4 GA
Description
The issue concerns the Hypermedia REST APIs module, which fails to properly check permissions. This allows remote attackers to obtain a WikiNode object via the "WikiNodeResource.getSiteWikiNodeByExternalReferenceCode" API endpoint, using the
externalReferenceCode variable.Recommendations
For Liferay Portal versions 7.4.1 through 7.4.3.4, consider restricting access to the WikiNodeResource API endpoint until a patch is available.
For Liferay DXP version 7.4 GA, restrict access to the WikiNodeResource API endpoint until a patch is available.
As a temporary workaround, consider disabling the WikiNodeResource.getSiteWikiNodeByExternalReferenceCode API endpoint until a patch is available.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Liferay Dxp
Liferay Portal