CVE-2020-7961: Liferay Portal Deserialization of Untrusted Data Vulnerability
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
Other sources
Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:com.liferay.portal.kernelto a version that resolves this vulnerability.Fixed in 4.35.3
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7961?
CVE-2020-7961 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2020-7961?
To fix CVE-2020-7961, upgrade to Liferay Portal version 7.2.1 CE GA2 or later.
Who is affected by CVE-2020-7961?
CVE-2020-7961 affects Liferay Portal versions prior to 7.2.1 CE GA2.
What type of vulnerability is CVE-2020-7961?
CVE-2020-7961 is a deserialization of untrusted data vulnerability.
Can CVE-2020-7961 be exploited remotely?
Yes, CVE-2020-7961 can be exploited remotely through JSON web services.