Maven package intelligence

com.liferay.portal:com.liferay.portal.kernel Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Maven package com.liferay.portal:com.liferay.portal.kernel, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
1
Known exploited vulnerability affecting com.liferay.portal:com.liferay.portal.kernel
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
com.liferay.portal:com.liferay.portal.kernel KEVs with sensor-observed exploitation activity

Review com.liferay.portal:com.liferay.portal.kernel exploitation against the versions you run

All one exploited com.liferay.portal:com.liferay.portal.kernel vulnerability tracked here is also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested com.liferay.portal:com.liferay.portal.kernel vulnerabilities

1 known exploited vulnerability affecting this package.

Vulnerability CISA KEV Added
CVE-2020-7961

Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services...

In CISA 03 Nov 2021

Recurring weakness patterns

Deserialization of Untrusted Data account for mapped occurrences across this com.liferay.portal:com.liferay.portal.kernel KEV portfolio.

Browse all KEVs →