[MAVEN:GHSA-W7PM-CC4V-F3G8] Deserialization of Untrusted Data in Liferay Portal

Severity Critical
Affected Packages 2
Fixed Packages 2
CVEs 1

Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).

ID
MAVEN:GHSA-W7PM-CC4V-F3G8
Severity
critical
URL
https://github.com/advisories/GHSA-w7pm-cc4v-f3g8
Published
2022-05-24T17:12:05
(2 years ago)
Modified
2023-01-27T05:02:28
(20 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.liferay.portal/com.liferay.portal.kernel com.liferay.portal com.liferay.portal.kernel <= 7.2.0
Fixed pkg:maven/com.liferay.portal/com.liferay.portal.kernel com.liferay.portal com.liferay.portal.kernel = 7.2.1
Affected pkg:maven/com.liferay.portal/com.liferay.portal-kernel com.liferay.portal com.liferay.portal-kernel <= 7.2.0
Fixed pkg:maven/com.liferay.portal/com.liferay.portal-kernel com.liferay.portal com.liferay.portal-kernel = 7.2.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...