Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with duplicated columns) can be used to obtain sensitive information about the content of bug reports.
References
Link | Resource |
---|---|
https://medium.com/@luanherrera/xs-searching-googles-bug-tracker-to-find-out-vulnerable-source-code-50d8135b7549 | Exploit Press/Media Coverage Third Party Advisory |
https://chromium.googlesource.com/infra/infra/+/0ff6b6453b6192987bd9240c1e872a7de5fb1313 | Patch Vendor Advisory |
https://www.reddit.com/r/netsec/comments/9yiidf/xssearching_googles_bug_tracker_to_find_out/ea2i7wz/ | Exploit Third Party Advisory |
Configurations
Information
Published : 2018-11-20 01:29
Updated : 2018-12-18 09:53
NVD link : CVE-2018-10099
Mitre link : CVE-2018-10099
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
- monorail