Vulnerability Description
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Liferay | Liferay Portal | < 7.2.1 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/157254/Liferay-Portal-Java-Unmarshalling-ReThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/158392/Liferay-Portal-Remote-Code-ExecutionThird Party AdvisoryVDB Entry
- https://portal.liferay.dev/learn/security/known-vulnerabilitiesBroken LinkVendor Advisory
- https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisheBroken LinkVendor Advisory
- https://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-ExploitThird Party Advisory
- http://packetstormsecurity.com/files/157254/Liferay-Portal-Java-Unmarshalling-ReThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/158392/Liferay-Portal-Remote-Code-ExecutionThird Party AdvisoryVDB Entry
- https://portal.liferay.dev/learn/security/known-vulnerabilitiesBroken LinkVendor Advisory
- https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisheBroken LinkVendor Advisory
- https://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-ExploitThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-US Government Resource
FAQ
What is CVE-2020-7961?
CVE-2020-7961 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
How severe is CVE-2020-7961?
CVE-2020-7961 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-7961?
Check the references section above for vendor advisories and patch information. Affected products include: Liferay Liferay Portal.