CVE-2020-7961
published 2020-03-20CVE-2020-7961: Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.77%
100.0th percentile
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | liferay_portal | < 7.2.1 | 7.2.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →FreakOut bots identify themselves on IRC with the nickname format [HAX| <OS> | <arch> | <cpu_count> ] <8-12 random chars>; detect this pattern in outbound IRC traffic. ↗
- →Compromised Liferay servers used as post-exploitation payload hosts on non-standard ports (not 80, 443, 8080); monitor outbound connections from internal hosts to Liferay CMS IPs on high/unusual ports. ↗
- →CVE-2020-7961 is part of the FreakOut 'unholy trinity' alongside CVE-2020-28188 and CVE-2021-3007; network sensors should correlate exploit attempts across all three CVEs from the same source IP as a high-confidence FreakOut indicator. ↗
- ·The FreakOut malware (out.py) is polymorphic and re-obfuscated on every download with random function/variable names, making static hash-based detection unreliable; behavioral detection is preferred. ↗
- ·The C2 IRC credentials (channel key, server address) are obfuscated and encoded multiple times within the bot code; extraction requires dynamic analysis or unpacking of the packing function. ↗
- ·Liferay servers observed as payload hosts were running the vulnerable CE version 6.2 (CVE-2020-7961 affects versions prior to 7.2.1 CE GA2); the servers appeared to be compromised third-party infrastructure, not attacker-owned. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Liferay Portal Deserialization of Untrusted Data Vulnerability
cisa·2021-11-03·CVSS 9.8
CVE-2020-7961 [CRITICAL] CWE-502 Liferay Portal Deserialization of Untrusted Data Vulnerability
Vulnerability: Liferay Portal Deserialization of Untrusted Data Vulnerability
Affected: Liferay Liferay Portal
Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-7961
Remediation Due Date: 2022-05-03
GHSA
Deserialization of Untrusted Data in Liferay Portal
ghsa·2022-05-24
CVE-2020-7961 [CRITICAL] CWE-502 Deserialization of Untrusted Data in Liferay Portal
Deserialization of Untrusted Data in Liferay Portal
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
OSV
Deserialization of Untrusted Data in Liferay Portal
osv·2022-05-24
CVE-2020-7961 [CRITICAL] Deserialization of Untrusted Data in Liferay Portal
Deserialization of Untrusted Data in Liferay Portal
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
VulnCheck
Liferay Portal Deserialization of Untrusted Data Vulnerability
vulncheck·2020·CVSS 9.8
CVE-2020-7961 [CRITICAL] CWE-502 Liferay Portal Deserialization of Untrusted Data Vulnerability
Liferay Portal Deserialization of Untrusted Data Vulnerability
Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.
Affected: Liferay Liferay Portal
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.imperva.com/blog/python-cryptominer-botnet-quickly-adopts-latest-vulnerabilities/; https://blog.checkpoint.com/2021/01/19/linux-users-should-patch-now-to-block-new-freakout-malware-which-exploits-new-vulnerabilities/; https://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnet/; https://blog.talosintelligence.com/2021/06/necro-python-bot-adds-new-tricks.html; https://www.trendmicro.com/en_us/research/21/g/threat-actors-
Suricata
ET WEB_SPECIFIC_APPS Liferay Unauthenticated RCE via JSONWS Inbound (CVE-2020-7961)
suricata·2021-01-29·CVSS 9.8
CVE-2020-7961 [CRITICAL] ET WEB_SPECIFIC_APPS Liferay Unauthenticated RCE via JSONWS Inbound (CVE-2020-7961)
ET WEB_SPECIFIC_APPS Liferay Unauthenticated RCE via JSONWS Inbound (CVE-2020-7961)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET WEB_SPECIFIC_APPS Liferay Unauthenticated RCE via JSONWS Inbound (CVE-2020-7961)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/api/jsonws/"; http.request_body; content:".c3p0.WrapperConnectionPoolDataSource"; fast_pattern; content:"&defaultData.userOverridesAsString=HexAsciiSerializedMap|3a|"; distance:0; reference:url,www.synacktiv.com/en/publications/how-to-exploit-liferay-cve-2020-7961-quick-journey-to-poc.html; reference:cve,2020-7961; classtype:attempted-admin; sid:2031592; rev:1; metadata:attack_target Server, created_at 2021_01_29, cve CVE_2020_7961, deployment Perimeter, deployment Internal, confiden
Suricata
ET EXPLOIT 401TRG Liferay RCE (CVE-2020-7961)
suricata·2020-12-11·CVSS 9.8
CVE-2020-7961 [CRITICAL] ET EXPLOIT 401TRG Liferay RCE (CVE-2020-7961)
ET EXPLOIT 401TRG Liferay RCE (CVE-2020-7961)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT 401TRG Liferay RCE (CVE-2020-7961)"; flow:established,to_server; http.uri; content:"/api/jsonws/expandocolumn/update-column"; nocase; http.request_body; content:"userOverridesAsString=HexAsciiSerializedMap"; nocase; fast_pattern; reference:cve,2020-7961; reference:url,www.synacktiv.com/en/publications/how-to-exploit-liferay-cve-2020-7961-quick-journey-to-poc.html; classtype:attempted-admin; sid:2031318; rev:1; metadata:created_at 2020_12_11, cve CVE_2020_7961, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_12_11;)
Exploit-DB
Liferay Portal - Java Unmarshalling via JSONWS RCE (Metasploit)
exploitdb·2020-04-16
CVE-2020-7961 Liferay Portal - Java Unmarshalling via JSONWS RCE (Metasploit)
Liferay Portal - Java Unmarshalling via JSONWS RCE (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'Liferay Portal Java Unmarshalling via JSONWS RCE',
'Description' => %q{
This module exploits a Java unmarshalling vulnerability via JSONWS in
Liferay Portal versions [
'Markus Wulftange', # Discovery
'Thomas Etrillard', # PoC
'wvu' # Module
],
'References' => [
['CVE', '2020-7961'],
['URL', 'https://codewhitesec.blogspot.com/2020/03/liferay-portal-json-vulns.html'],
['URL', 'https://www.synacktiv.com/posts/pentest/how-to-exploit-liferay-cve-2020-7961-quick-journey-to-poc.html'],
['URL', 'https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_pu
Nuclei
Liferay Security Checks
nuclei·CVSS 9.8
CVE-2020-7961 [CRITICAL] Liferay Security Checks
Liferay Security Checks
A simple workflow that runs all liferay related nuclei templates on a given target.
Template:
id: liferay-workflow
info:
name: Liferay Security Checks
author: dwisiswant0
description: A simple workflow that runs all liferay related nuclei templates on a given target.
workflows:
- template: http/exposed-panels/liferay-portal.yaml
subtemplates:
- template: http/cves/2020/CVE-2020-7961.yaml
Metasploit
Liferay Portal Java Unmarshalling via JSONWS RCE
metasploit
Liferay Portal Java Unmarshalling via JSONWS RCE
Liferay Portal Java Unmarshalling via JSONWS RCE
This module exploits a Java unmarshalling vulnerability via JSONWS in Liferay Portal versions < 6.2.5 GA6, 7.0.6 GA7, 7.1.3 GA4, and 7.2.1 GA2 to execute code as the Liferay user. Tested against 7.2.0 GA1.
Nuclei
Liferay Login Panel - Detect
nuclei·CVSS 9.8
CVE-2020-7961 [CRITICAL] Liferay Login Panel - Detect
Liferay Login Panel - Detect
Liferay login panel was detected,
Template:
id: liferay-portal
info:
name: Liferay Login Panel - Detect
author: organiccrap,dwisiswant0,ricardomaia
severity: info
description: Liferay login panel was detected,
reference:
- https://www.liferay.com/
- https://github.com/mzer0one/CVE-2020-7961-POC
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
cwe-id: CWE-200
cpe: cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 3
vendor: liferay
product: liferay_portal
shodan-query:
- http.favicon.hash:129457226
- cpe:"cpe:2.3:a:liferay:liferay_portal"
fofa-query: icon_hash=129457226
tags: panel,liferay,portal,discovery
http:
- method: GET
path:
- "{{BaseURL}}"
- "{{BaseURL}}/api/jsonws"
- "{{BaseURL}}/api/jso
Nuclei
Liferay Portal Unauthenticated < 7.2.1 CE GA2 - Remote Code Execution
nuclei·CVSS 9.8
CVE-2020-7961 [CRITICAL] Liferay Portal Unauthenticated < 7.2.1 CE GA2 - Remote Code Execution
Liferay Portal Unauthenticated < 7.2.1 CE GA2 - Remote Code Execution
Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
Template:
id: CVE-2020-7961
info:
name: Liferay Portal Unauthenticated < 7.2.1 CE GA2 - Remote Code Execution
author: dwisiswant0
severity: critical
description: Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
impact: |
Unauthenticated attackers can execute arbitrary code via JSON web services, leading to complete server compromise and access to all portal data.
remediation: |
Upgrade Liferay Portal to version 7.2.1 CE GA2 or later to mitigate the vulnerability.
reference:
- https://www.synacktiv.com/en/publications/how-to-exploit
Trendmicro
Analyzing ProxyShell-related Incidents via Trend Micro Managed XDR
blogs_trendmicro·2021-11-17
Analyzing ProxyShell-related Incidents via Trend Micro Managed XDR
Cyberbedrohungen
## Analyzing ProxyShell-related Incidents via Trend Micro Managed XDR
In this blog entry, we will take a look at the ProxyShell vulnerabilities that were being exploited in these events, and dive deeper into the notable post-exploitation routines that were used in four separate incidents involving these web shell attacks.
By: Sherif Magdy, Abdelrhman Sharshar Nov 17, 2021 Read time: ( words)
Save to Folio
The Trend Micro™ Managed XDR team recently observed a surge in server-side compromises — ProxyShell-related intrusions on Microsoft Exchange in particular via the Managed XDR service and other incident response engagements. These compromises, which occurred across different sectors in the Middle East, were most often observed in environments using on-premise implemen
Trendmicro
Analyzing ProxyShell-related Incidents via Trend Micro Managed XDR
blogs_trendmicro·2021-11-17
Analyzing ProxyShell-related Incidents via Trend Micro Managed XDR
Cyber Threats
## Analyzing ProxyShell-related Incidents via Trend Micro Managed XDR
In this blog entry, we will take a look at the ProxyShell vulnerabilities that were being exploited in these events, and dive deeper into the notable post-exploitation routines that were used in four separate incidents involving these web shell attacks.
By: Sherif Magdy, Abdelrhman Sharshar 2021/11/17 Read time: ( words)
Save to Folio
The Trend Micro™ Managed XDR team recently observed a surge in server-side compromises — ProxyShell-related intrusions on Microsoft Exchange in particular via the Managed XDR service and other incident response engagements. These compromises, which occurred across different sectors in the Middle East, were most often observed in environments using on-premise implementatio
Trendmicro
Analyzing ProxyShell-related Incidents via Trend Micro Managed XDR
blogs_trendmicro·2021-11-17
Analyzing ProxyShell-related Incidents via Trend Micro Managed XDR
Cyber Threats
# Analyzing ProxyShell-related Incidents via Trend Micro Managed XDR
In this blog entry, we will take a look at the ProxyShell vulnerabilities that were being exploited in these events, and dive deeper into the notable post-exploitation routines that were used in four separate incidents involving these web shell attacks.
By: Sherif Magdy, Abdelrhman Sharshar
2021/11/17
Read time: ( words)
Save to Folio
The Trend Micro™ Managed XDR team recently observed a surge in server-side compromises — ProxyShell-related intrusions on Microsoft Exchange in particular via the Managed XDR service and other incident response engagements. These compromises, which occurred across different sectors in the Middle East, were most often observed in environments using on-premise implementatio
Trendmicro
Analyzing ProxyShell-related Incidents via Trend Micro Managed XDR
blogs_trendmicro·2021-11-17
Analyzing ProxyShell-related Incidents via Trend Micro Managed XDR
Ciberamenazas
## Analyzing ProxyShell-related Incidents via Trend Micro Managed XDR
In this blog entry, we will take a look at the ProxyShell vulnerabilities that were being exploited in these events, and dive deeper into the notable post-exploitation routines that were used in four separate incidents involving these web shell attacks.
By: Sherif Magdy, Abdelrhman Sharshar Nov 17, 2021 Read time: ( words)
Save to Folio
The Trend Micro™ Managed XDR team recently observed a surge in server-side compromises — ProxyShell-related intrusions on Microsoft Exchange in particular via the Managed XDR service and other incident response engagements. These compromises, which occurred across different sectors in the Middle East, were most often observed in environments using on-premise implementat
Trendmicro
Analyzing ProxyShell-related Incidents via Trend Micro Managed XDR
blogs_trendmicro·2021-11-17
Analyzing ProxyShell-related Incidents via Trend Micro Managed XDR
Cyber Threats
## Analyzing ProxyShell-related Incidents via Trend Micro Managed XDR
In this blog entry, we will take a look at the ProxyShell vulnerabilities that were being exploited in these events, and dive deeper into the notable post-exploitation routines that were used in four separate incidents involving these web shell attacks.
By: Abdelrhman Sharshar Nov 17, 2021 Read time: ( words)
Save to Folio
The Trend Micro™ Managed XDR team recently observed a surge in server-side compromises — ProxyShell-related intrusions on Microsoft Exchange in particular via the Managed XDR service and other incident response engagements. These compromises, which occurred across different sectors in the Middle East, were most often observed in environments using on-premise implementations of Micros
Checkpoint
FreakOut – Leveraging Newest Vulnerabilities for creating a Botnet
blogs_checkpoint·2021-01-19·CVSS 9.8
CVE-2020-28188 [CRITICAL] FreakOut – Leveraging Newest Vulnerabilities for creating a Botnet
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## FreakOut – Leveraging Newest Vulnerabilities for creating a Botnet
Research By: Omer Ventura, Ori Hamama, Network Research
## Introduction
Recently, Check Point Research encountered se
Greynoiseio
How to Identify & Disrupt C2s Using Graph Analysis
blogs_greynoiseio
How to Identify & Disrupt C2s Using Graph Analysis
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
HackerOne
CVE-2020-7961 RCE Liferay Portal Unauthenticated via https://████████/
hackerone·2024-10-25·CVSS 9.8
CVE-2020-7961 [CRITICAL] CVE-2020-7961 RCE Liferay Portal Unauthenticated via https://████████/
CVE-2020-7961 RCE Liferay Portal Unauthenticated via https://████████/
poc:
```
POST /api/jsonws/invoke HTTP/1.1
Host: ████████
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:124.0) Gecko/20100101 Firefox/124.0
Content-Length: 4939
Content-Type: application/x-www-form-urlencoded
Referer: https://██████//api/jsonws?contextName=&signature=%2Fexpandocolumn%2Fadd-column-4-tableId-name-type-defaultData
cmd2: systeminfo
Accept-Encoding: gzip
cmd=%7B%22%2Fexpandocolumn%2Fadd-column%22%3A%7B%7D%7D&p_auth=tdmrl&formDate=1597704739243&tableId=1&name=A&type=1&%2BdefaultData:com.mchange.v2.c3p0.WrapperConnectionPoolDataSource=%7B%22userOverridesAsString%22%3A%22HexAsciiSerializedMap%3AACED0005737200116A6176612E7574696C2E48617368536574BA44859596B8B7340300007870770C000000023F40000000000001737200346F72
http://packetstormsecurity.com/files/157254/Liferay-Portal-Java-Unmarshalling-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/158392/Liferay-Portal-Remote-Code-Execution.htmlhttps://portal.liferay.dev/learn/security/known-vulnerabilitieshttps://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/117954271https://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnet/http://packetstormsecurity.com/files/157254/Liferay-Portal-Java-Unmarshalling-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/158392/Liferay-Portal-Remote-Code-Execution.htmlhttps://portal.liferay.dev/learn/security/known-vulnerabilitieshttps://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/117954271https://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnet/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-7961
2020-03-20
Published
2021-11-03
Added to CISA KEV
Exploited in the wild