VDB
RHSA-2013:0187
RHSA-2013:0187
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT) 2.4 through 2.5 Final, as used in JBoss Operations Network (ON) 3.1.1 and possibly other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2012-4563.
Risk Scores
CVSS 2.0
4.300000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Operations Network 3.1 |
Timeline
- Jan 23, 2013 CVE Published
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Jun 27, 2026 CVE Updated
- Jun 27, 2026 Distribution Patch
- Jun 27, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2013:0187 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/knowledge/docs/ advisory
- https://www.cve.org/CVERecord?id=CVE-2012-5920 advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=em&version=3.1.2 advisory
- https://developers.google.com/web-toolkit/release-notes#Release_Notes_Current advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=871690 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2013/rhsa-2013_0187.json advisory
- https://access.redhat.com/security/cve/CVE-2012-5920 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2012-5920 advisory