MEDIUM
GateIn: XSS due to improper url escaping
Published Dec 23, 2013
4.3
MEDIUMCVSS 2.0
EPSS 0.98%
Description
Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal component in Red Hat JBoss Portal 6.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected products
No data.
- 6.1.0
No data.
Red Hat JBoss Portal Platform 6.1
portal
Fixed · RHSA-2013:1843
Red Hat JBoss Portal 5
portal
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Portal Platform 6.1 | portal | Fixed | RHSA-2013:1843 |
| Red Hat JBoss Portal 5 | portal | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://rhn.redhat.com/errata/RHSA-2013-1843.html vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2013-4424 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1019052 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-4424
- https://www.cve.org/CVERecord?id=CVE-2013-4424
| Link | Providers | Tags |
|---|---|---|
| http://rhn.redhat.com/errata/RHSA-2013-1843.html | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2013-4424 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1019052 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-4424 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-4424 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 23, 2013
Updated Aug 6, 2024
Reserved Jun 12, 2013
Link CVE-2013-4424
CISA Vulnrichment
Updated n/a