CVE-2022-42124
n/a n/a, digital experience platform, liferay portal 취약점
ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.2 fix pack 9 through fix pack 18, 7.3 before update 4, and DXP 7.4 GA allows remote attackers to consume an excessive amount of server resources via a crafted payload injected into the 'name' field of a layout prototype.
- 대응 우선순위
- 점검
- CVSS
- 7.5
- EPSS
- 1.23% 백분위 66.0% · 2026.08.02 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2022.11.15