Red Hat Bugzilla – Bug 913327
CVE-2013-0314 GateIn Portal: remote unauthenticated site import
Last modified: 2014-10-20 20:04:31 EDT
The GateIn Portal Export / Import Gadget allows an export zip to be uploaded and imported to a site without authentication. A remote attacker could use this flaw to modify the content of a site, remove the site or modify access controls applied to portlets in the site.
Acknowledgements: This issue was discovered by Nick Scavelli of Red Hat.
This issue has been addressed in following products: JBoss Enterprise Portal Platform 5.2.2 Via RHSA-2013:0613 https://rhn.redhat.com/errata/RHSA-2013-0613.html