The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-11-15T00:00:00
Updated: 2024-08-03T13:03:45.085Z
Reserved: 2022-10-03T00:00:00
Link: CVE-2022-42126
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-11-15T01:15:13.267
Modified: 2024-11-21T07:24:25.027
Link: CVE-2022-42126
Redhat
No data.