Medium severity4.3NVD Advisory· Published Nov 15, 2022· Updated Jul 9, 2026
CVE-2022-42126
CVE-2022-42126
Description
The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.liferay.portal:release.portal.bomMaven | >= 7.3.5, < 7.4.3.48 | 7.4.3.48 |
Affected products
7cpe:2.3:a:liferay:digital_experience_platform:7.3:-:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:liferay:digital_experience_platform:7.3:-:*:*:*:*:*:*
- cpe:2.3:a:liferay:digital_experience_platform:7.4:-:*:*:*:*:*:*
- cpe:2.3:a:liferay:digital_experience_platform:7.4:update1:*:*:*:*:*:*
- osv-coords2 versions
>= 7.3.0, <= 7.3.0+ 1 more
- (no CPE)range: >= 7.3.0, <= 7.3.0
- (no CPE)range: >= 7.3.5, < 7.4.3.48
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-642h-mx8q-47p2ghsaADVISORY
- issues.liferay.com/browse/LPE-17593nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-42126ghsaADVISORY
- portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42126nvdVendor AdvisoryWEB
- liferay.comghsaWEB
News mentions
0No linked articles in our index yet.