Vulnerabilities > Liferay > Digital Experience Platform > High

DATE CVE VULNERABILITY TITLE RISK
2022-11-15 CVE-2022-42123 Path Traversal vulnerability in Liferay Digital Experience Platform and Liferay Portal
A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.
network
low complexity
liferay CWE-22
7.5
2022-11-15 CVE-2022-42124 Unspecified vulnerability in Liferay Digital Experience Platform and Liferay Portal
ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.2 fix pack 9 through fix pack 18, 7.3 before update 4, and DXP 7.4 GA allows remote attackers to consume an excessive amount of server resources via a crafted payload injected into the 'name' field of a layout prototype.
network
low complexity
liferay
7.5
2022-11-15 CVE-2022-42125 Path Traversal vulnerability in Liferay Digital Experience Platform and Liferay Portal
Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers to create or overwrite existing files on the filesystem via the deployment of a malicious plugin/module.
network
low complexity
liferay CWE-22
7.5
2022-03-02 CVE-2021-38266 Unspecified vulnerability in Liferay Portal
The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and 7.2 before fix pack 5 does not correctly import users from LDAP, which allows remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exist in LDAP.
network
low complexity
liferay
7.5