Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
References
Configurations
History
14 Mar 2025, 20:38
Type | Values Removed | Values Added |
---|---|---|
References | () https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/117954271 - Vendor Advisory, Broken Link |
Information
Published : 2020-03-20 19:15
Updated : 2025-03-14 20:38
NVD link : CVE-2020-7961
Mitre link : CVE-2020-7961
CVE.ORG link : CVE-2020-7961
JSON object : View
Products Affected
liferay
- liferay_portal
CWE
CWE-502
Deserialization of Untrusted Data