Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with an unsupported axis) can be used to obtain sensitive information about the content of bug reports.
References
Link | Resource |
---|---|
https://medium.com/@luanherrera/xs-searching-googles-bug-tracker-to-find-out-vulnerable-source-code-50d8135b7549 | Exploit Press/Media Coverage Third Party Advisory |
https://chromium.googlesource.com/infra/infra/+/77ef00cb53d90c9d1f984eca434d828de5c167a5 | Patch Vendor Advisory |
https://www.reddit.com/r/netsec/comments/9yiidf/xssearching_googles_bug_tracker_to_find_out/ea2i7wz/ | Exploit Third Party Advisory |
Configurations
Information
Published : 2018-11-20 01:29
Updated : 2018-12-18 09:53
NVD link : CVE-2018-19334
Mitre link : CVE-2018-19334
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
- monorail