Junglewise Threat Intelligence

CVE-2020-7961: Deserialization of Untrusted Data in Liferay Portal

CVE-2020-7961 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2022-05-24

Technologies: Liferay Portal, com.liferay.portal:com.liferay.portal.kernel (Maven). Vendors: Liferay, Maven.

Executive brief

Liferay Portal contains a deserialization of untrusted data vulnerability in its JSON web services (JSONWS). Remote attackers can exploit this to execute arbitrary code on the server without authentication.

Affected products

  • Liferay Liferay Portal prior to 7.2.1 CE GA2

Timeline

  • 2020-03-20: disclosed: Approximate date based on CVE ID and vendor advisory timeline
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory: NVD publication date
  • 2021-01-19: exploited: Reported as leveraged in the 'FreakOut' botnet campaign

Related threats