CVE-2020-13445
Summary
| CVE | CVE-2020-13445 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-10 19:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not restrict user access to sensitive objects, which allows remote authenticated users to execute arbitrary code via crafted FreeMarker and Velocity templates. |
Risk And Classification
Problem Types: CWE-74 | CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Liferay | Liferay Portal | 7.1 | ga1 | All | All |
| Application | Liferay | Liferay Portal | 7.1 | ga2 | All | All |
| Application | Liferay | Liferay Portal | 7.1 | ga3 | All | All |
| Application | Liferay | Liferay Portal | 7.1.1 | ga2 | All | All |
| Application | Liferay | Liferay Portal | 7.2 | ga1 | All | All |
| Application | Liferay | Liferay Portal | 7.3 | ga1 | All | All |
| Application | Liferay | Liferay Portal | 7.3 | ga2 | All | All |
| Application | Liferay | Liferay Portal | 7.1 | ga1 | All | All |
| Application | Liferay | Liferay Portal | 7.1 | ga2 | All | All |
| Application | Liferay | Liferay Portal | 7.1 | ga3 | All | All |
| Application | Liferay | Liferay Portal | 7.1.1 | ga2 | All | All |
| Application | Liferay | Liferay Portal | 7.2 | ga1 | All | All |
| Application | Liferay | Liferay Portal | 7.3 | ga1 | All | All |
| Application | Liferay | Liferay Portal | 7.3 | ga2 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [LPE-17023] Remote code execution (RCE) with FreeMarker/Velocity templates - Liferay Issues | MISC | issues.liferay.com | Patch, Vendor Advisory |
| GHSL-2020-043: Server-side template injection in Liferay - CVE-2020-13445 - GitHub Security Lab | MISC | securitylab.github.com | Exploit, Third Party Advisory |
| CST-7302 Remote code execution with FreeMarker/Velocity templates (CVE-2020-13445) | CONFIRM | portal.liferay.dev | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.