A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7363 | A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin. |
Github GHSA |
GHSA-hffx-r282-w2g9 | Path Traversal in Liferay Portal |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 05 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-05T17:25:07.238Z
Reserved: 2022-10-03T00:00:00.000Z
Link: CVE-2022-42123
Updated: 2024-08-03T13:03:45.528Z
Status : Modified
Published: 2022-11-15T01:15:13.053
Modified: 2025-09-05T18:15:36.977
Link: CVE-2022-42123
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA