Description
A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7363 | A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin. |
Github GHSA |
GHSA-hffx-r282-w2g9 | Path Traversal in Liferay Portal |
References
History
Fri, 05 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-05T17:25:07.238Z
Reserved: 2022-10-03T00:00:00.000Z
Link: CVE-2022-42123
Updated: 2024-08-03T13:03:45.528Z
Status : Modified
Published: 2022-11-15T01:15:13.053
Modified: 2025-09-05T18:15:36.977
Link: CVE-2022-42123
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA