CVE-2022-42131
MEDIUMLiferay Digital Experience Platform - Missing SSL Certificate Validation in Dynamic Data Mapping REST Data Providers
Title source: llmDescription
Certain Liferay products are affected by: Missing SSL Certificate Validation in the Dynamic Data Mapping module's REST data providers. This affects Liferay Portal 7.1.0 through 7.4.2 and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3.
References (3)
Core 3
Core References
Vendor Advisory
http://liferay.com
Vendor Advisory
https://issues.liferay.com/browse/LPE-17377
Scores
CVSS v3
4.8
EPSS
0.0013
EPSS Percentile
31.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-295
Status
published
Products (5)
com.liferay.portal/release.portal.bom
7.1.0 - 7.4.3.4Maven
liferay/digital_experience_platform
7.1 (27 CPE variants)
liferay/digital_experience_platform
7.2 (17 CPE variants)
liferay/digital_experience_platform
7.3 (3 CPE variants)
liferay/liferay_portal
7.1.0 - 7.4.3.4
Published
Nov 15, 2022
Tracked Since
Feb 18, 2026