CVE-2022-42125
CVSS v3.1
7.5 (High)
EPSS
0.11 % (46th)
Affected Products
2
Advisories
1
Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers to create or overwrite existing files on the filesystem via the deployment of a malicious plugin/module.
Weaknesses
- CWE-22
- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CVE Status
- PUBLISHED
- CNA
- MITRE
- Published Date
-
2022-11-15 01:15:13
(22 months ago) - Updated Date
-
2022-11-18 16:51:04
(22 months ago)
Affected Products
Loading...
Loading...
Loading...
Configuration #1
|
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...