Liferay Portal versions 7.2.0 through 7.4.3.15 and Liferay DXP versions prior to 7.4 update 16, 7.3 update 4, and 7.2 fix pack 17 use PBKDF2-HMAC-SHA1 as the default password hashing algorithm with a low work factor. This configuration results in password hashes that can be cracked significantly faster than intended, exposing user credentials to brute-force attacks if the password database is compromised.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is not a single exploit dropper but a focused vulnerability-research and validation project for Liferay Portal CE 7.0.3 GA4. Most files are Markdown research artifacts: inventory, threat model, prior art, candidate analyses, judge verdicts, and live-validation writeups. The actual code is concentrated in tools/gadget_ser.py and tools/liferay_ga4_check.py, which generate Java-serialization payloads in pure Python and automate validation of the documented findings. The main exploit capability is unauthenticated RCE against Liferay JSONWS (CVE-2020-7961 class). The documented and live-validated chain targets /api/jsonws/invoke or service-specific JSONWS methods, abuses parameter type override to instantiate com.mchange.v2.c3p0.WrapperConnectionPoolDataSource, sets userOverridesAsString to a HexAsciiSerializedMap payload, triggers ObjectInputStream.readObject(), and uses an AspectJWeaver gadget to write arbitrary files, including a JSP under the Tomcat ROOT webapp. The repo explicitly reports live end-to-end RCE as root. Beyond RCE, the repository documents multiple additional exploit primitives: pre-auth blind SSRF via /xmlrpc/pingback with internal port oracle behavior; pre-auth and authenticated arbitrary document-version disclosure via /o/sync/download/* using versionId IDOR; pre-auth image disclosure via /image/*?img_id=; pre-auth Web Content Display request-parameter override for cross-site article disclosure; authenticated XSL template SSRF/RCE and Velocity/Freemarker file/property disclosure; captcha brute-force and forgot-password abuse; and several conditional or deployment-specific issues involving poller, tunnel, Axis, OpenSocial, WSRP, SSO, and import/export. Repository structure is methodical: candidates/ contains initial vulnerability hypotheses by attack surface; judge/ contains independent source-based validation/refutation; verified/ contains live exploitation evidence and cleanup notes; ENTRYPOINTS.md and ENV.md define the target surface and lab environment; FINDINGS.md and REPORT.md summarize outcomes; tools/ contains the only operational exploit code. Overall, this is a mature operational research repo with actionable exploit intelligence, especially for default Liferay GA4 deployments.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.