Executive brief
Liferay Portal contains a deserialization of untrusted data vulnerability in its JSON web services (JSONWS). Remote attackers can exploit this to execute arbitrary code on the server without authentication.
Affected products
- Liferay Liferay Portal prior to 7.2.1 CE GA2
Timeline
- 2020-03-20: disclosed: Approximate date based on CVE ID and vendor advisory timeline
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory: NVD publication date
- 2021-01-19: exploited: Reported as leveraged in the 'FreakOut' botnet campaign