PT-2022-8909 · Liferay · Liferay Portal Server
Published
2022-01-28
·
Updated
2024-08-04
·
CVE-2020-28884
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Liferay Portal Server versions 7.2.0 GA1 through 7.3.5 GA6
Description
The issue allows an administrator user to inject Groovy script, enabling the execution of any OS command on the Liferay Portal Server. This is disputed by the developer as it is considered a feature for administrators to run Groovy scripts, rather than a design flaw.
Recommendations
For versions 7.2.0 GA1 through 7.3.5 GA6, consider restricting the ability to inject Groovy scripts to minimize the risk of unauthorized OS command execution.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Liferay Portal Server