Red Hat JBoss Portal is the open source implementation of the Java EE suite
of services and Portal services running atop Red Hat JBoss Enterprise
Application Platform. It comprises a set of offerings for enterprise
customers who are looking for pre-configured profiles of JBoss Middleware
components that have been tested and certified together to provide an
integrated experience.
Multiple cross-site scripting (XSS) flaws were found in the GateIn Portal
component. If a remote attacker could trick a user, who was logged into the
GateIn Portal interface, into visiting a specially crafted URL, it would
lead to arbitrary web script execution in the context of the userβs GateIn
Portal session. (CVE-2013-4424)
Red Hat would like to thank Cloud Technology Development Department, Ricoh
Company, Ltd. for reporting this issue.
All users of Red Hat JBoss Portal 6.1.0 as provided from the Red Hat
Customer Portal are advised to install this update.