{"id":"CVE-2022-28977","details":"HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack 17 through 25, 7.2 fix pack 5 through 14, and 7.3 before service pack 3 can be circumvented by using multiple forward slashes, which allows remote attackers to redirect users to arbitrary external URLs via the (1) 'redirect` parameter (2) `FORWARD_URL` parameter, and (3) others parameters that rely on HtmlUtil.escapeRedirect.","aliases":["GHSA-w397-9p2j-6x23"],"modified":"2026-04-10T04:47:06.904185Z","published":"2022-09-22T01:15:10.753Z","references":[{"type":"WEB","url":"http://liferay.com"},{"type":"FIX","url":"https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-28977-htmlutil.escaperedirect-circumvention-with-multiple-forward-slash"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/liferay/liferay-portal","events":[{"introduced":"0"},{"last_affected":"4ffdd7225ef4a5fd922703263a3006a741a4d8d0"},{"introduced":"0"},{"last_affected":"0515646c8f638f202d107469cc147172fc7685de"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"7.3-sp1"},{"introduced":"0"},{"last_affected":"7.3-sp2"}]}}],"versions":["6.1.0-b1","6.1.0-b2","6.1.0-b3","6.1.0-b4","6.1.0-rc1","6.2.0-b1","6.2.0-b2","6.2.0-m2","6.2.0-m3","6.2.0-m4","6.2.0-m5","6.2.0-m6","7.0.0-m1","7.0.0-m2","7.0.0-m3","7.0.0-m4","7.0.0-m5","7.1.0-a1","7.1.0-a2","7.1.0-b1","7.1.0-b2","7.1.0-m1","7.1.0-m2","7.2.0-a1","7.2.0-b1","7.2.0-b2","7.2.0-b3","7.2.0-m2","7.3.0-ga1","7.3.1-ga2","7.3.2-ga3","sync-3.0.0-b1","sync-3.0.1-b2","sync-3.0.10-ga2","sync-3.0.2-b3","sync-3.0.3-b4","sync-3.0.4-b5","sync-3.0.5-b6","sync-3.0.6-b7","sync-3.0.7-b8","sync-3.0.8-b9","sync-3.0.9-ga1","sync-3.1.0-ga1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-28977.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"7.0-NA"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0-fix_pack_100"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0-fix_pack_101"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0-fix_pack_91"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0-fix_pack_92"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0-fix_pack_93"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0-fix_pack_94"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0-fix_pack_95"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0-fix_pack_96"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0-fix_pack_97"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0-fix_pack_98"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0-fix_pack_99"}]},{"events":[{"introduced":"0"},{"last_affected":"7.1-NA"}]},{"events":[{"introduced":"0"},{"last_affected":"7.1-fix_pack_17"}]},{"events":[{"introduced":"0"},{"last_affected":"7.1-fix_pack_18"}]},{"events":[{"introduced":"0"},{"last_affected":"7.1-fix_pack_19"}]},{"events":[{"introduced":"0"},{"last_affected":"7.1-fix_pack_20"}]},{"events":[{"introduced":"0"},{"last_affected":"7.1-fix_pack_21"}]},{"events":[{"introduced":"0"},{"last_affected":"7.1-fix_pack_22"}]},{"events":[{"introduced":"0"},{"last_affected":"7.1-fix_pack_23"}]},{"events":[{"introduced":"0"},{"last_affected":"7.1-fix_pack_24"}]},{"events":[{"introduced":"0"},{"last_affected":"7.1-fix_pack_25"}]},{"events":[{"introduced":"0"},{"last_affected":"7.2-NA"}]},{"events":[{"introduced":"0"},{"last_affected":"7.2-fix_pack_10"}]},{"events":[{"introduced":"0"},{"last_affected":"7.2-fix_pack_11"}]},{"events":[{"introduced":"0"},{"last_affected":"7.2-fix_pack_12"}]},{"events":[{"introduced":"0"},{"last_affected":"7.2-fix_pack_13"}]},{"events":[{"introduced":"0"},{"last_affected":"7.2-fix_pack_14"}]},{"events":[{"introduced":"0"},{"last_affected":"7.2-fix_pack_5"}]},{"events":[{"introduced":"0"},{"last_affected":"7.2-fix_pack_6"}]},{"events":[{"introduced":"0"},{"last_affected":"7.2-fix_pack_7"}]},{"events":[{"introduced":"0"},{"last_affected":"7.2-fix_pack_8"}]},{"events":[{"introduced":"0"},{"last_affected":"7.2-fix_pack_9"}]},{"events":[{"introduced":"0"},{"last_affected":"7.3-NA"}]},{"events":[{"introduced":"7.3.1"},{"fixed":"7.4.3.4"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}