ZeroHour

CVE-2020-7961

KEV PoC large

Deserialization RCE in Liferay Portal via JSON Web Services

CISA: Liferay Portal Deserialization of Untrusted Data Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

Liferay Portal contains a deserialization of untrusted data flaw (CWE-502) that allows remote attackers to execute arbitrary code through the product's JSON web services. An attacker triggers it by sending crafted, untrusted serialized data to the portal's JSON web services endpoints; the available data does not specify an affected version range or authentication requirements. Successful exploitation yields remote code execution on the portal server, a foothold attackers can use to pivot into the wider environment. Any organization running Liferay Portal is affected, with internet-facing deployments at highest risk; public internet-wide scans have counted tens of thousands of exposed instances. The vulnerability is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with a 99.9% EPSS (100th percentile), indicating active or near-certain exploitation, though no public PoC is documented, ransomware use is unknown, and CVSS has not been scored.

What to do: Apply Liferay's updates per vendor instructions as required by CISA KEV, prioritizing internet-facing portals, and use the Liferay advisory to identify affected instances since no version range is given here. If patching must wait, restrict external access to the JSON web services endpoints and monitor for exploitation, given the in-the-wild status and 99.9% EPSS.

Affected
Liferay Portal
Estimated exposure
large≈20,000-40,000 internet-exposed Liferay Portal instances (public internet-wide scan counts) — Public internet-wide scan counts have historically indexed tens of thousands of exposed Liferay Portal instances, and internal enterprise portal deployments mean the true installed base is likely higher.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).

CISA Known Exploited Vulnerability
Affected
Liferay Liferay Portal
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
liferay
Products
liferay portal
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news