Cross-Site Search Vulnerability in Google Monorail
CVE-2018-10099

5.3MEDIUM

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
20 November 2018

Summary

Google Monorail, prior to April 4, 2018, contains a Cross-Site Search (XS-Search) vulnerability where CSV downloads are susceptible to Cross-Site Request Forgery (CSRF). This flaw allows an attacker to manipulate download requests, potentially exposing sensitive information regarding bug report content by leveraging the manner in which download times are calculated for requests that contain duplicated columns.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.