CVE-2022-42126

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2022-42126
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-42126.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-42126
Aliases
Published
2022-11-15T01:15:13Z
Modified
2024-07-05T21:26:42Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI.

References

Affected packages

Git / github.com/liferay/liferay-portal

Affected ranges

Type
GIT
Repo
https://github.com/liferay/liferay-portal
Events