[MAVEN:GHSA-HFFX-R282-W2G9] Path Traversal in Liferay Portal

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.

Package Affected Version
pkg:maven/com.liferay.portal/release.portal.bom >= 7.3.3, < 7.4.3.19
Package Fixed Version
pkg:maven/com.liferay.portal/release.portal.bom = 7.4.3.19
ID
MAVEN:GHSA-HFFX-R282-W2G9
Severity
high
URL
https://github.com/advisories/GHSA-hffx-r282-w2g9
Published
2022-11-15T12:00:16
(22 months ago)
Modified
2023-02-01T05:03:56
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.liferay.portal/release.portal.bom com.liferay.portal release.portal.bom >= 7.3.3 < 7.4.3.19
Fixed pkg:maven/com.liferay.portal/release.portal.bom com.liferay.portal release.portal.bom = 7.4.3.19
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...