oss-sec mailing list archives
CVE request: XSS is Google Web Toolkit (GWT)
From: David Jorm <djorm () redhat com>
Date: Mon, 29 Oct 2012 21:26:12 -0400 (EDT)
I note that with the release of google web toolkit (GWT) 2.5, a security flaw has been resolved. The best details I can find are at: https://developers.google.com/web-toolkit/release-notes#Release_Notes_2_4_0 (scroll to "Security vulnerability in GWT 2.4") The release notes state: "Recently, the GWT team discovered a cross-site scripting vulnerability in the 2.4 Beta and Release Candidate releases (not in v2.3 GA or v2.4 GA). This vulnerability was partially fixed in the 2.4 GA release and completely fixed in the 2.5 GA release. If you have an app that's been built with 2.4 then you'll need to get the latest 2.5 release, recompile your app, and redeploy." I can't find any details on the flaw, a CVE ID, a public bug or a commit. I have contacted security@google asking for these details, but no response yet. Can we assign a CVE ID to this flaw in the absence of these details? Thanks -- David Jorm / Red Hat Security Response Team
Current thread:
- CVE request: XSS is Google Web Toolkit (GWT) David Jorm (Oct 29)
- Re: CVE request: XSS is Google Web Toolkit (GWT) Kurt Seifried (Oct 29)
- Re: CVE request: XSS is Google Web Toolkit (GWT) Kurt Seifried (Oct 30)