← back
CVE-2022-42126

CVE-2022-42126

CVSS 4.3 MEDIUMEPSS 0.8%CWE-284
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.3EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
15 Nov 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →