Liferay DXP 7.4 Update 29

CPE Details

Liferay DXP 7.4 Update 29
7.4
2022-09-23
11h33 +00:00
2022-09-26
13h45 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:liferay:dxp:7.4:update_29:*:*:*:*:*:*

Informations

Vendor

liferay

Product

dxp

Version

7.4

Update

update_29

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-42114 2022-10-17 22h00 +00:00 A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML.
5.4
Medium
CVE-2022-38512 2022-09-21 22h17 +00:00 The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.
6.5
Medium
CVE-2022-39975 2022-09-21 21h35 +00:00 The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the preview of a "Content Page" type page, allowing attackers to view unpublished "Content Page" pages via URL manipulation.
4.3
Medium