CVE-2022-42129

An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form entries via the `formInstanceRecordId` parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:liferay:digital_experience_platform:7.3:-:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.4:-:*:*:*:*:*:*
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*

History

18 Nov 2022, 16:00

Type Values Removed Values Added
CPE cpe:2.3:a:liferay:digital_experience_platform:7.4:-:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:7.3:-:*:*:*:*:*:*
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*
References (MISC) https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42129 - (MISC) https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42129 - Vendor Advisory
References (MISC) http://liferay.com - (MISC) http://liferay.com - Vendor Advisory
References (MISC) https://issues.liferay.com/browse/LPE-17448 - (MISC) https://issues.liferay.com/browse/LPE-17448 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CWE CWE-639
First Time Liferay
Liferay liferay Portal
Liferay digital Experience Platform

15 Nov 2022, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-11-15 02:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-42129

Mitre link : CVE-2022-42129

CVE.ORG link : CVE-2022-42129


JSON object : View

Products Affected

liferay

  • digital_experience_platform
  • liferay_portal
CWE
CWE-639

Authorization Bypass Through User-Controlled Key