CVE-2022-42123

HIGH

Liferay Portal 7.3.3-7.4.3.18 and DXP 7.3-7.4 - Path Traversal via Elasticsearch Sidecar Plugin Installation

Title source: llm
STIX 2.1

Description

A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.

Scores

CVSS v3 7.5
EPSS 0.0042
EPSS Percentile 62.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (4)
com.liferay.portal/release.portal.bom 7.3.3 - 7.4.3.19Maven
liferay/digital_experience_platform 7.3
liferay/digital_experience_platform 7.4
liferay/liferay_portal 7.3.3 - 7.4.3.19
Published Nov 15, 2022
Tracked Since Feb 18, 2026