CVE-2020-13445: GHSL-2020-043: Server-side template injection in Liferay - CVE-2020-13445
A user with privileges to edit FreeMarker or Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Liferay.
Other sources
In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not restrict user access to sensitive objects, which allows remote authenticated users to execute arbitrary code via crafted FreeMarker and Velocity templates.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13445?
CVE-2020-13445 is rated as high severity due to its ability to allow unauthorized access and remote code execution.
How do I fix CVE-2020-13445?
To fix CVE-2020-13445, upgrade to Liferay Portal version 7.3.2 or Liferay DXP 7.0 fix pack 92 or later.
Who is affected by CVE-2020-13445?
CVE-2020-13445 affects users of Liferay Portal versions prior to 7.3.2 and various earlier fix packs for versions 7.0, 7.1, and 7.2.
What types of attacks can exploit CVE-2020-13445?
CVE-2020-13445 can be exploited by authenticated remote users to execute arbitrary code using specially crafted FreeMarker and Velocity templates.
Is there a workaround for CVE-2020-13445?
There are no official workarounds for CVE-2020-13445, and upgrading to the fixed versions is recommended.