当前位置:网站首页>Analysis of liferayportal jsonws deserialization vulnerability (cve-2020-7961)
Analysis of liferayportal jsonws deserialization vulnerability (cve-2020-7961)
2022-06-29 10:19:00 【Qianli ZLP】
One 、 Vulnerability description
2020 year 03 month 20 Japan ,Code White Found the impact Liferay Portal edition 6.1、6.2、7.0、7.1 and 7.2 Multiple critical levels of JSON Deserialization vulnerability . They are allowed to pass JSON web service API Execute unauthenticated remote code . repair Liferay Portal Version has 6.2 GA6、7.0 GA7、7.1 GA4 and 7.2 GA2.
Liferay( also called Liferay Portal) Is an open source portal project , The project contains a complete J2EE application , In order to create Web Site 、 Intranet , To show the appropriate customer base the documents and applications that match them .
Two 、 Affects version
Liferay Portal: 6.1、6.2、7.0、7.1、7.2
3、 ... and 、 Vulnerability analysis
Liferay Portal Provides Json Web Service service , For some callable endpoints , If a method provides Object Parameter type , Then it can be constructed to conform to Java Beans Can use malicious class , Transfer constructed json Deserialize string ,y When deserializing, the malicious class will be called automatically setter Method and default constructor .
JODD Serialization and deserialization
边栏推荐
猜你喜欢
随机推荐
Function pointer, function pointer array, calculator + transfer table, etc
1098 insertion or heap sort (25 points)
Binding mechanism of JVM methods
2019.11.3 learning summary
Nacos registry cluster
另类实现 ScrollView 下拉头部放大
Codeforces Round #652 (Div. 2)
To 3 -- the last programming challenge
1146 Topological Order (25 分)
在VMware workstation中安装WMware ESXi 6.5.0并进行配置
Substring score - Ultra detailed version - the last programming challenge
Database common interview questions (with answers)
六度空间 bfs
2019.11.20 training summary
Acwing271 [teacher Yang's photographic arrangement] [linear DP]
2021 team programming ladder competition - Simulation Competition
Summary after the 2009 ICPC Shanghai regional competition
nacos注册中心集群
A method of creating easy to manage and maintain thread by C language
走迷宫 bfs 中等+——最后的编程挑战









