Back CVE-2022-28981 Path traversal vulnerability in Hypermedia REST APIs


Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote attackers to access files outside of com.liferay.headless.discovery.web/META-INF/resources via the `parameter` parameter.


null (null)


Liferay Portal 7.4: There is no patch available for Liferay Portal 7.4. Instead, users should upgrade to Liferay Portal 7.4 GA4 (

Publication date: Mon, 24 Jan 2022 16:00:00 +0000

The security advisories on this page is for Liferay's open source projects (e.g., Liferay Portal). Security advisories for Liferay's enterprise offerings (e.g., Liferay DXP) are available in Help Center.