CVE-2018-19334
Summary
| CVE | CVE-2018-19334 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-11-20 09:29:00 UTC |
| Updated | 2023-11-07 02:55:00 UTC |
| Description | Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with an unsupported axis) can be used to obtain sensitive information about the content of bug reports. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| XS-Searching Google’s bug tracker to find out vulnerable source code | medium.com | ||
| Involder comments on XS-Searching Google’s bug tracker to find out vulnerable source code | MISC | www.reddit.com | Exploit, Third Party Advisory |
| XS-Searching Google’s bug tracker to find out vulnerable source code | MISC | medium.com | Exploit, Press/Media Coverage, Third Party Advisory |
| 77ef00cb53d90c9d1f984eca434d828de5c167a5 - infra/infra - Git at Google | MISC | chromium.googlesource.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.