CRITICAL9.8
GHSA-w7pm-cc4v-f3g8
Deserialization of Untrusted Data in Liferay Portal
Quick fix
GHSA-w7pm-cc4v-f3g8 — com.liferay.portal:com.liferay.portal.kernel: upgrade to the fixed version with the command below.
# pom.xml: bump <version>4.35.3</version> for com.liferay.portal:com.liferay.portal.kernelDetails
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/com.liferay.portal:com.liferay.portal.kernel
Introduced in:
0Fixed in: 4.35.3Fix
# pom.xml: bump <version>4.35.3</version> for com.liferay.portal:com.liferay.portal.kernelReferences
- https://nvd.nist.gov/vuln/detail/CVE-2020-7961[ADVISORY]
- https://github.com/liferay/liferay-portal[PACKAGE]
- https://github.com/liferay/liferay-portal/blob/7.2.1-ga2/portal-kernel/bnd.bnd[WEB]
- https://portal.liferay.dev/learn/security/known-vulnerabilities[WEB]
- https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/117954271[WEB]
- https://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnet[WEB]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-7961[WEB]
- http://packetstormsecurity.com/files/157254/Liferay-Portal-Java-Unmarshalling-Remote-Code-Execution.html[WEB]
- http://packetstormsecurity.com/files/158392/Liferay-Portal-Remote-Code-Execution.html[WEB]