<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>Security Vulnerability /api/jsonws - Liferay Versions</title>
  <link rel="self" href="https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=118840654" />
  <subtitle>Security Vulnerability /api/jsonws - Liferay Versions</subtitle>
  <id>https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=118840654</id>
  <updated>2026-04-05T09:30:27Z</updated>
  <dc:date>2026-04-05T09:30:27Z</dc:date>
  <entry>
    <title>RE: Security Vulnerability /api/jsonws - Liferay Versions</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=118842426" />
    <author>
      <name>Christoph Rabel</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=118842426</id>
    <updated>2020-04-01T11:09:36Z</updated>
    <published>2020-04-01T11:09:36Z</published>
    <summary type="html">Please read:&lt;br /&gt;&lt;a href="https://liferay.dev/blogs/-/blogs/security-patches-for-liferay-portal-6-2-7-0-and-7-1"&gt;https://liferay.dev/blogs/-/blogs/security-patches-for-liferay-portal-6-2-7-0-and-7-1&lt;/a&gt;&lt;br /&gt;7.2.1 GA2 is not affected, a patch exists for 7.1 GA4.&lt;br /&gt;Personal opinion: For a new project I would go for 7.3. There were lots of nice fixes and improvements.</summary>
    <dc:creator>Christoph Rabel</dc:creator>
    <dc:date>2020-04-01T11:09:36Z</dc:date>
  </entry>
  <entry>
    <title>Security Vulnerability /api/jsonws - Liferay Versions</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=118840653" />
    <author>
      <name>Fredi B</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=118840653</id>
    <updated>2020-04-01T09:22:03Z</updated>
    <published>2020-04-01T09:22:03Z</published>
    <summary type="html">Hello Liferay Friends,&lt;br /&gt;currently we are investigating the possibility to use Liferay CE as Portal solution. &lt;br /&gt;&lt;br /&gt;Sadly one of our security managers came across this exploit of the liferay&lt;strong&gt; /jsonws API&lt;/strong&gt; that enables attackers to even get a remote shell on the server.&lt;br /&gt;&lt;a href="https://www.synacktiv.com/posts/pentest/how-to-exploit-liferay-cve-2020-7961-quick-journey-to-poc.html"&gt;https://www.synacktiv.com/posts/pentest/how-to-exploit-liferay-cve-2020-7961-quick-journey-to-poc.html&lt;/a&gt;&lt;br /&gt;&lt;a href="https://www.synacktiv.com/posts/pentest/how-to-exploit-liferay-cve-2020-7961-quick-journey-to-poc.html"&gt;&lt;/a&gt;&lt;br /&gt;Can you provide further information if this security problem is &lt;strong&gt;not existing&lt;/strong&gt; on &lt;strong&gt;7.1.3 GA4&lt;/strong&gt; or &lt;strong&gt;7.2.1 GA2 &lt;/strong&gt;because these two versions &lt;strong&gt;&lt;/strong&gt;seem to fit our requirements.&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;Greetings,&lt;br /&gt;Fredi</summary>
    <dc:creator>Fredi B</dc:creator>
    <dc:date>2020-04-01T09:22:03Z</dc:date>
  </entry>
</feed>
