Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with duplicated columns) can be used to obtain sensitive information about the content of bug reports.
References
Configurations
History
No history.
Information
Published : 2018-11-20 09:29
Updated : 2024-11-21 03:40
NVD link : CVE-2018-10099
Mitre link : CVE-2018-10099
CVE.ORG link : CVE-2018-10099
JSON object : View
Products Affected
- monorail
CWE
CWE-352
Cross-Site Request Forgery (CSRF)