Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote attackers to access files outside of com.liferay.headless.discovery.web/META-INF/resources via the `parameter` parameter.
References
Configurations
History
No history.
Information
Published : 2022-09-22 01:15
Updated : 2024-11-21 06:58
NVD link : CVE-2022-28981
Mitre link : CVE-2022-28981
CVE.ORG link : CVE-2022-28981
JSON object : View
Products Affected
liferay
- liferay_portal
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')