7.5
CVSSv3

CVE-2022-42123

Published: 15/11/2022 Updated: 18/11/2022
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 up to and including 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows malicious users to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

liferay digital experience platform 7.3

liferay liferay portal

liferay digital experience platform 7.4