// For flags

CVE-2022-42124

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.2 fix pack 9 through fix pack 18, 7.3 before update 4, and DXP 7.4 GA allows remote attackers to consume an excessive amount of server resources via a crafted payload injected into the 'name' field of a layout prototype.

Vulnerabilidad ReDoS en LayoutPageTemplateEntryUpgradeProcess en Liferay Portal 7.3.2 hasta 7.4.3.4 y Liferay DXP 7.2 fix pack 9 hasta fix pack 18, 7.3 antes de la actualización 4 y DXP 7.4 GA permite a atacantes remotos consumir una cantidad excesiva de recursos del servidor a través de un payload manipulado inyectado en el campo 'nombre' de un prototipo de diseño.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-10-03 CVE Reserved
  • 2022-11-15 CVE Published
  • 2024-07-06 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-1333: Inefficient Regular Expression Complexity
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Liferay
Search vendor "Liferay"
Digital Experience Platform
Search vendor "Liferay" for product "Digital Experience Platform"
7.2
Search vendor "Liferay" for product "Digital Experience Platform" and version "7.2"
fix_pack_10
Affected
Liferay
Search vendor "Liferay"
Digital Experience Platform
Search vendor "Liferay" for product "Digital Experience Platform"
7.2
Search vendor "Liferay" for product "Digital Experience Platform" and version "7.2"
fix_pack_11
Affected
Liferay
Search vendor "Liferay"
Digital Experience Platform
Search vendor "Liferay" for product "Digital Experience Platform"
7.2
Search vendor "Liferay" for product "Digital Experience Platform" and version "7.2"
fix_pack_12
Affected
Liferay
Search vendor "Liferay"
Digital Experience Platform
Search vendor "Liferay" for product "Digital Experience Platform"
7.2
Search vendor "Liferay" for product "Digital Experience Platform" and version "7.2"
fix_pack_13
Affected
Liferay
Search vendor "Liferay"
Digital Experience Platform
Search vendor "Liferay" for product "Digital Experience Platform"
7.2
Search vendor "Liferay" for product "Digital Experience Platform" and version "7.2"
fix_pack_14
Affected
Liferay
Search vendor "Liferay"
Digital Experience Platform
Search vendor "Liferay" for product "Digital Experience Platform"
7.2
Search vendor "Liferay" for product "Digital Experience Platform" and version "7.2"
fix_pack_15
Affected
Liferay
Search vendor "Liferay"
Digital Experience Platform
Search vendor "Liferay" for product "Digital Experience Platform"
7.2
Search vendor "Liferay" for product "Digital Experience Platform" and version "7.2"
fix_pack_16
Affected
Liferay
Search vendor "Liferay"
Digital Experience Platform
Search vendor "Liferay" for product "Digital Experience Platform"
7.2
Search vendor "Liferay" for product "Digital Experience Platform" and version "7.2"
fix_pack_9
Affected
Liferay
Search vendor "Liferay"
Digital Experience Platform
Search vendor "Liferay" for product "Digital Experience Platform"
7.3
Search vendor "Liferay" for product "Digital Experience Platform" and version "7.3"
-
Affected
Liferay
Search vendor "Liferay"
Digital Experience Platform
Search vendor "Liferay" for product "Digital Experience Platform"
7.4
Search vendor "Liferay" for product "Digital Experience Platform" and version "7.4"
-
Affected
Liferay
Search vendor "Liferay"
Liferay Portal
Search vendor "Liferay" for product "Liferay Portal"
>= 7.3.2 < 7.4.3.5
Search vendor "Liferay" for product "Liferay Portal" and version " >= 7.3.2 < 7.4.3.5"
-
Affected