Medium severity6.5NVD Advisory· Published Sep 22, 2022· Updated Jul 9, 2026
CVE-2022-38512
CVE-2022-38512
Description
The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.liferay:com.liferay.translation.webMaven | < 2.0.58 | 2.0.58 |
com.liferay.portal:release.dxp.bomMaven | >= 7.4.13.u8, < 7.4.13.u37 | 7.4.13.u37 |
Affected products
34cpe:2.3:a:liferay:dxp:7.4:update_10:*:*:*:*:*:*+ 29 more
- cpe:2.3:a:liferay:dxp:7.4:update_10:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_11:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_12:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_13:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_14:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_15:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_16:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_17:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_18:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_19:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_20:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_21:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_22:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_23:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_24:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_25:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_26:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_27:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_28:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_29:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_30:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_31:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_32:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_33:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_34:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_35:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_36:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_3:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_8:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.4:update_9:*:*:*:*:*:*
- ghsa-coords2 versions
>= 7.4.13.u8, < 7.4.13.u37+ 1 more
- (no CPE)range: >= 7.4.13.u8, < 7.4.13.u37
- (no CPE)range: < 2.0.58
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-h9ww-wjg4-jvvgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-38512ghsaADVISORY
- portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-38512nvdRelease NotesVendor Advisory
- liferay.comghsaWEB
- github.com/liferay/liferay-portal/commit/1934094578ddcd2c1f3d37593b493d3991a6a20fghsaWEB
- github.com/liferay/liferay-portal/commit/48fd5698fc1935a90e9c5013c328dbc369ba353dghsaWEB
- liferay.atlassian.net/browse/LPE-17610ghsaWEB
- liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2022-38512ghsaWEB
News mentions
0No linked articles in our index yet.