legacy-knowledge-base
公開されました Jun. 30, 2025

CVE-2020-28885 および CVE-2020-28884

written-by

Neil Cuzon

How To articles are not official guidelines or officially supported documentation. They are community-contributed content and may not always reflect the latest updates to Liferay DXP. We welcome your feedback to improve How To articles!

While we make every effort to ensure this Knowledge Base is accurate, it may not always reflect the most recent updates or official guidelines.We appreciate your understanding and encourage you to reach out with any feedback or concerns.

legacy-article

learn-legacy-article-disclaimer-text

問題

  • LiferayのCVE-2020-28885とCVE-2020-28884の脆弱性について知りたい。

  • CVEは、管理者ユーザがGogo ShellモジュールとGroovyスクリプトを通してそれぞれコマンドを注入し、Liferayポータルサーバ上で任意のOSコマンドを実行できる脆弱性であると主張しています。

環境

  • DXP 7.4

解像度

  • CVE(CVE-2020-28885とCVE-2020-28884)はどちらも、一般的に管理者ユーザに関連するパーミッションと一致する意図的な動作を記述しています。

  • Liferayは、管理者がGroovyスクリプトを実行するだけでなく、Gogo Shellにアクセスしてコマンドを実行することが許可されていることは想定内の機能であるため、これらは脆弱性ではないと主張している。 したがって、設計上の欠陥や脆弱性ではない。
  • どちらも安全に無視することができるし、gogoシェルとgroovyスクリプトを無効にすることもできる。

追加情報:

did-this-article-resolve-your-issue

legacy-knowledge-base