A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-11-15T00:00:00
Updated: 2024-08-03T13:03:45.528Z
Reserved: 2022-10-03T00:00:00
Link: CVE-2022-42123
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-11-15T01:15:13.053
Modified: 2024-11-21T07:24:24.557
Link: CVE-2022-42123
Redhat
No data.