Description
A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.
Remediation
References
http://liferay.com
https://issues.liferay.com/browse/LPE-17518
https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42123
Related Vulnerabilities
CVE-2016-0789 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2018-1331 Vulnerability in maven package org.apache.storm:storm-core
CVE-2017-7672 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2019-10344 Vulnerability in maven package io.jenkins:configuration-as-code
CVE-2017-5662 Vulnerability in maven package org.apache.xmlgraphics:batik-rasterizer