The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38512.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_11"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_13"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_14"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_15"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_16"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_17"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_18"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_19"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_20"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_21"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_22"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_23"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_24"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_25"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_26"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_27"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_28"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_29"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_30"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_31"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_32"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_33"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_34"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_35"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_36"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4-update_9"
}
]
}
]