Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote attackers to access files outside of com.liferay.headless.discovery.web/META-INF/resources via the `parameter` parameter.
References
Link | Resource |
---|---|
http://liferay.com | Product |
https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-28981-path-traversal-vulnerability-in-hypermedia-rest-apis | Release Notes Vendor Advisory |
Configurations
Information
Published : 2022-09-21 18:15
Updated : 2022-09-23 10:41
NVD link : CVE-2022-28981
Mitre link : CVE-2022-28981
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
liferay
- liferay_portal