← Back

CVE-2022-42123

nvd nist
Published: Nov 15, 2022Modified: Jul 9, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.

Affected (3)

2 products
Digital Experience Platform
Liferay Portal
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
Version 7.3
Version 7.4
From 7.3.3 to 7.4.3.19

Timeline

No history available yet.