{"api_version":"1","generated_at":"2026-07-23T08:09:14+00:00","cve":"CVE-2012-5920","urls":{"html":"https://cve.report/CVE-2012-5920","api":"https://cve.report/api/cve/CVE-2012-5920.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-5920","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-5920"},"summary":{"title":"CVE-2012-5920","description":"Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT) 2.4 through 2.5 Final, as used in JBoss Operations Network (ON) 3.1.1 and possibly other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this issue exists because of an incomplete fix for CVE-2012-4563.","state":"PUBLISHED","assigner":"mitre","published_at":"2012-11-20 00:55:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2012/10/31/1","name":"http://www.openwall.com/lists/oss-security/2012/10/31/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - Re: CVE request: XSS is Google Web Toolkit (GWT)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://developers.google.com/web-toolkit/release-notes#Release_Notes_2_4_0","name":"https://developers.google.com/web-toolkit/release-notes#Release_Notes_2_4_0","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Google Web Toolkit Release Notes - Google Web Toolkit — Google Developers","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2013-0187.html","name":"http://rhn.redhat.com/errata/RHSA-2013-0187.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/57538","name":"http://www.securityfocus.com/bid/57538","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Google Web Toolkit CVE-2012-5920 Cross Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/80331","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/80331","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-5920","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-5920","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"5920","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"google","cpe5":"web_toolkit","cpe6":"2.4","cpe7":"beta","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5920","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"google","cpe5":"web_toolkit","cpe6":"2.4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5920","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"google","cpe5":"web_toolkit","cpe6":"2.5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5920","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"google","cpe5":"web_toolkit","cpe6":"2.5.0","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"5920","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"google","cpe5":"web_toolkit","cpe6":"2.5.0","cpe7":"rc2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T21:21:27.886Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"web-toolkit-unspecified-xss(80331)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/80331"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://developers.google.com/web-toolkit/release-notes#Release_Notes_2_4_0"},{"name":"57538","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/57538"},{"name":"RHSA-2013:0187","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2013-0187.html"},{"name":"[oss-security] 20121030 Re: CVE request: XSS is Google Web Toolkit (GWT)","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2012/10/31/1"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-10-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT) 2.4 through 2.5 Final, as used in JBoss Operations Network (ON) 3.1.1 and possibly other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this issue exists because of an incomplete fix for CVE-2012-4563."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"web-toolkit-unspecified-xss(80331)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/80331"},{"tags":["x_refsource_CONFIRM"],"url":"https://developers.google.com/web-toolkit/release-notes#Release_Notes_2_4_0"},{"name":"57538","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/57538"},{"name":"RHSA-2013:0187","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2013-0187.html"},{"name":"[oss-security] 20121030 Re: CVE request: XSS is Google Web Toolkit (GWT)","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2012/10/31/1"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2012-5920","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT) 2.4 through 2.5 Final, as used in JBoss Operations Network (ON) 3.1.1 and possibly other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this issue exists because of an incomplete fix for CVE-2012-4563."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"web-toolkit-unspecified-xss(80331)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/80331"},{"name":"https://developers.google.com/web-toolkit/release-notes#Release_Notes_2_4_0","refsource":"CONFIRM","url":"https://developers.google.com/web-toolkit/release-notes#Release_Notes_2_4_0"},{"name":"57538","refsource":"BID","url":"http://www.securityfocus.com/bid/57538"},{"name":"RHSA-2013:0187","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2013-0187.html"},{"name":"[oss-security] 20121030 Re: CVE request: XSS is Google Web Toolkit (GWT)","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2012/10/31/1"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2012-5920","datePublished":"2012-11-20T00:00:00.000Z","dateReserved":"2012-11-19T00:00:00.000Z","dateUpdated":"2024-08-06T21:21:27.886Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-11-20 00:55:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:web_toolkit:2.4:beta:*:*:*:*:*:*","matchCriteriaId":"47F35A1B-64D5-4201-8213-D6ED3B545035"},{"vulnerable":true,"criteria":"cpe:2.3:a:google:web_toolkit:2.4.0:*:*:*:*:*:*:*","matchCriteriaId":"3C755D82-C65D-4F4A-89C5-F5608A2A404B"},{"vulnerable":true,"criteria":"cpe:2.3:a:google:web_toolkit:2.5.0:*:*:*:*:*:*:*","matchCriteriaId":"880EFC35-AD4D-4849-8812-29735FB2A86F"},{"vulnerable":true,"criteria":"cpe:2.3:a:google:web_toolkit:2.5.0:rc1:*:*:*:*:*:*","matchCriteriaId":"B1EE7E78-6FE4-43BE-AE5E-9075A87524FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:google:web_toolkit:2.5.0:rc2:*:*:*:*:*:*","matchCriteriaId":"1FFED626-3FE6-421B-9A67-A3F542F7344C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"5920","Ordinal":"1","Title":"CVE-2012-5920","CVE":"CVE-2012-5920","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"5920","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT) 2.4 through 2.5 Final, as used in JBoss Operations Network (ON) 3.1.1 and possibly other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: this issue exists because of an incomplete fix for CVE-2012-4563.","Type":"Description","Title":"CVE-2012-5920"},{"CveYear":"2012","CveId":"5920","Ordinal":"2","NoteData":"2012-11-19","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"5920","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}