当前位置:网站首页>Analysis of liferayportal jsonws deserialization vulnerability (cve-2020-7961)
Analysis of liferayportal jsonws deserialization vulnerability (cve-2020-7961)
2022-06-29 10:19:00 【Qianli ZLP】
One 、 Vulnerability description
2020 year 03 month 20 Japan ,Code White Found the impact Liferay Portal edition 6.1、6.2、7.0、7.1 and 7.2 Multiple critical levels of JSON Deserialization vulnerability . They are allowed to pass JSON web service API Execute unauthenticated remote code . repair Liferay Portal Version has 6.2 GA6、7.0 GA7、7.1 GA4 and 7.2 GA2.
Liferay( also called Liferay Portal) Is an open source portal project , The project contains a complete J2EE application , In order to create Web Site 、 Intranet , To show the appropriate customer base the documents and applications that match them .
Two 、 Affects version
Liferay Portal: 6.1、6.2、7.0、7.1、7.2
3、 ... and 、 Vulnerability analysis
Liferay Portal Provides Json Web Service service , For some callable endpoints , If a method provides Object Parameter type , Then it can be constructed to conform to Java Beans Can use malicious class , Transfer constructed json Deserialize string ,y When deserializing, the malicious class will be called automatically setter Method and default constructor .
JODD Serialization and deserialization
边栏推荐
猜你喜欢

A method of creating easy to manage and maintain thread by C language

Flutter 基础组件之 Container

Application of keil5 integrated development environment for single chip microcomputer

Sixteen system counter and flow lamp

Simulation problem of two stacks

EDA and VHDL question bank

单片机集成开发环境Keil5的使用

The Stones Game【取石子博弈 & 思维】

520 diamond Championship 2021

RecyclerView 通用适配器封装
随机推荐
在VMware workstation中安装WMware ESXi 6.5.0并进行配置
2019.10.27 training summary
Pipeline details of IPC (interprocess communication)
EDA and VHDL question bank
HDU 6778 car (group enumeration -- > shape pressure DP)
2019.10.23 training summary
L2-3 这是二叉搜索树吗?-题解超精彩哦
函数指针、函数指针数组、计算器+转移表等归纳总结
Setinterval, setTimeout and requestanimationframe
CodeForces - 1151B 思维
L2-3 is this a binary search tree- The explanation is wonderful
51nod1277 maximum value in string [KMP]
十六制计数器和流水灯
The stones game
Codeforces Round #645 (Div. 2)
Simulation problem of two stacks
2019-11-10 training summary
2019.11.17训练总结
Codeforces Round #659 (Div. 2)
Nacos registry cluster