Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.liferay.portal:com.liferay.portal.kernel(Maven) | 0 | 4.35.3 | N/A |
CVSS Metrics