Notre sélection d'alertes et avis SSI.
Sources : US Cert, Cert EU, Cert FR, Cnil, VulDB.

vendredi 17 avril 2020

Liferay Portal - Exploited Remote Code Execution Vulnerabilities (CERT-EU Security Advisory 2020-022)

On March 20, 2020, Code White released two proof-of-concepts for vulnerabilities on Liferay Portal. These vulnerabilities were patched by Liferay. However, CERT-EU is aware of these vulnerabilities being actually exploited by malicious threat actors to gain illicit access to unpatched exposed servers. This second vulnerability is massively scanned for exploitation and CERT-EU is aware of ongoing campaigns exploiting this vulnerability as several proof of concept are available online. It is strongly recommended to check the version of Liferay portal being used and look for traces of intrusion on the potentially impacted servers.

Lien vers l'article source

Auteur: Cert EU

Catégories: CertEUNombre de vues: 116


Événements SSI