CVE-2022-42126

The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:liferay:digital_experience_platform:7.3:-:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:-:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:update1:*:*:*:*:*:*
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*

History

30 Apr 2025, 15:15

Type Values Removed Values Added
CWE CWE-284

21 Nov 2024, 07:24

Type Values Removed Values Added
References () http://liferay.com - Vendor Advisory () http://liferay.com - Vendor Advisory
References () https://issues.liferay.com/browse/LPE-17593 - Vendor Advisory () https://issues.liferay.com/browse/LPE-17593 - Vendor Advisory
References () https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42126 - Vendor Advisory () https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42126 - Vendor Advisory

Information

Published : 2022-11-15 01:15

Updated : 2025-04-30 15:15


NVD link : CVE-2022-42126

Mitre link : CVE-2022-42126

CVE.ORG link : CVE-2022-42126


JSON object : View

Products Affected

liferay

  • liferay_portal
  • digital_experience_platform
CWE
NVD-CWE-noinfo CWE-284

Improper Access Control