CVE-2022-42131
Summary
| CVE | CVE-2022-42131 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-15 02:15:12 UTC |
| Updated | 2026-07-09 01:17:49 UTC |
| Description | Certain Liferay products are affected by: Missing SSL Certificate Validation in the Dynamic Data Mapping module's REST data providers. This affects Liferay Portal 7.1.0 through 7.4.2 and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3. |
Risk And Classification
Primary CVSS: v3.1 4.8 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS: 0.002430000 probability, percentile 0.154180000 (date 2026-07-13)
Problem Types: CWE-295 | n/a | CWE-295 CWE-295 Improper Certificate Validation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 4.8 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
| 3.1 | ADP | DECLARED | 4.8 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 4.8 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Liferay | Digital Experience Platform | 7.1 | - | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_1 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_10 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_11 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_12 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_13 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_14 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_15 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_16 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_17 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_18 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_19 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_2 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_20 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_21 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_22 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_23 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_24 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_25 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_26 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_3 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_4 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_5 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_6 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_7 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_8 | All | All |
| Application | Liferay | Digital Experience Platform | 7.1 | fix_pack_9 | All | All |
| Application | Liferay | Digital Experience Platform | 7.2 | - | All | All |
| Application | Liferay | Digital Experience Platform | 7.2 | fix_pack_1 | All | All |
| Application | Liferay | Digital Experience Platform | 7.2 | fix_pack_10 | All | All |
| Application | Liferay | Digital Experience Platform | 7.2 | fix_pack_11 | All | All |
| Application | Liferay | Digital Experience Platform | 7.2 | fix_pack_12 | All | All |
| Application | Liferay | Digital Experience Platform | 7.2 | fix_pack_13 | All | All |
| Application | Liferay | Digital Experience Platform | 7.2 | fix_pack_14 | All | All |
| Application | Liferay | Digital Experience Platform | 7.2 | fix_pack_15 | All | All |
| Application | Liferay | Digital Experience Platform | 7.2 | fix_pack_16 | All | All |
| Application | Liferay | Digital Experience Platform | 7.2 | fix_pack_2 | All | All |
| Application | Liferay | Digital Experience Platform | 7.2 | fix_pack_3 | All | All |
| Application | Liferay | Digital Experience Platform | 7.2 | fix_pack_4 | All | All |
| Application | Liferay | Digital Experience Platform | 7.2 | fix_pack_5 | All | All |
| Application | Liferay | Digital Experience Platform | 7.2 | fix_pack_6 | All | All |
| Application | Liferay | Digital Experience Platform | 7.2 | fix_pack_7 | All | All |
| Application | Liferay | Digital Experience Platform | 7.2 | fix_pack_8 | All | All |
| Application | Liferay | Digital Experience Platform | 7.2 | fix_pack_9 | All | All |
| Application | Liferay | Digital Experience Platform | 7.3 | - | All | All |
| Application | Liferay | Digital Experience Platform | 7.3 | fix_pack_1 | All | All |
| Application | Liferay | Digital Experience Platform | 7.3 | fix_pack_2 | All | All |
| Application | Liferay | Liferay Portal | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2022-42131 DDMRESTDataProvider vulnerable to man-in-the-middle attack | af854a3a-2127-422b-91ae-364da2661108 | portal.liferay.dev | Vendor Advisory |
| [LPE-17377] LSV-934: DDMRESTDataProvider vulnerable to man-in-the-middle attack - Liferay Issues | af854a3a-2127-422b-91ae-364da2661108 | issues.liferay.com | Vendor Advisory |
| Digital Experience Software Tailored to Your Needs | Liferay | MITRE | liferay.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.