CVE-2020-7961
KEV PoC largeDeserialization RCE in Liferay Portal via JSON Web Services
CISA: Liferay Portal Deserialization of Untrusted Data Vulnerability
Liferay Portal contains a deserialization of untrusted data flaw (CWE-502) that allows remote attackers to execute arbitrary code through the product's JSON web services. An attacker triggers it by sending crafted, untrusted serialized data to the portal's JSON web services endpoints; the available data does not specify an affected version range or authentication requirements. Successful exploitation yields remote code execution on the portal server, a foothold attackers can use to pivot into the wider environment. Any organization running Liferay Portal is affected, with internet-facing deployments at highest risk; public internet-wide scans have counted tens of thousands of exposed instances. The vulnerability is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with a 99.9% EPSS (100th percentile), indicating active or near-certain exploitation, though no public PoC is documented, ransomware use is unknown, and CVSS has not been scored.
What to do: Apply Liferay's updates per vendor instructions as required by CISA KEV, prioritizing internet-facing portals, and use the Liferay advisory to identify affected instances since no version range is given here. If patching must wait, restrict external access to the JSON web services endpoints and monitor for exploitation, given the in-the-wild status and 99.9% EPSS.
| Liferay Portal | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
- Affected
- Liferay Liferay Portal
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- liferay
- Products
- liferay portal
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H