7.5
CVSSv3

CVE-2022-42124

Published: 15/11/2022 Updated: 08/08/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 up to and including 7.4.3.4 and Liferay DXP 7.2 fix pack 9 through fix pack 18, 7.3 before update 4, and DXP 7.4 GA allows remote malicious users to consume an excessive amount of server resources via a crafted payload injected into the 'name' field of a layout prototype.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

liferay digital experience platform 7.2

liferay digital experience platform 7.3

liferay liferay portal

liferay digital experience platform 7.4