CVE-2022-28977 HtmlUtil.escapeRedirect circumvention with multiple forward slash

Description

HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2 can be circumvented by using multiple forward slashes, which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, and (3) others parameters that rely on HtmlUtil.escapeRedirect.

Severity

6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

Affected Version(s)

  • Liferay Portal 7.3.1 - 7.3.7
  • Liferay Portal 7.4.0 - 7.4.2

Fixed Version(s)

Publication date: Mon, 24 Jan 2022 16:00:00 +0000

The security advisories on this page is for Liferay's open source projects (e.g., Liferay Portal). Security advisories for Liferay's enterprise offerings (e.g., Liferay DXP) are available in Help Center.