Medium severity5.4NVD Advisory· Published Nov 15, 2022· Updated Jul 9, 2026
CVE-2022-42119
CVE-2022-42119
Description
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.liferay.commerce:com.liferay.commerce.catalog.webMaven | < 4.0.8 | 4.0.8 |
com.liferay.portal:release.dxp.bomMaven | >= 7.3.0, < 7.3.10.u8 | 7.3.10.u8 |
Affected products
11cpe:2.3:a:liferay:dxp:7.3:-:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:liferay:dxp:7.3:-:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.3:update_1:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.3:update_2:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.3:update_3:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.3:update_4:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.3:update_5:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.3:update_6:*:*:*:*:*:*
- cpe:2.3:a:liferay:dxp:7.3:update_7:*:*:*:*:*:*
- ghsa-coords2 versionspkg:maven/com.liferay.commerce/com.liferay.commerce.catalog.webpkg:maven/com.liferay.portal/release.dxp.bom
< 4.0.8+ 1 more
- (no CPE)range: < 4.0.8
- (no CPE)range: >= 7.3.0, < 7.3.10.u8
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-wjfm-qxg2-q679ghsaADVISORY
- issues.liferay.com/browse/LPE-17632nvdIssue TrackingVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-42119ghsaADVISORY
- portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42119nvdVendor Advisory
- liferay.comghsaWEB
- github.com/liferay/liferay-portal/commit/2e02110747dd5cccb978623545bfa1f3ad0a5602ghsaWEB
- web.archive.org/web/20221115040019/https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42119ghsaWEB
News mentions
0No linked articles in our index yet.