First published: Tue Nov 20 2018(Updated: )
Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with duplicated columns) can be used to obtain sensitive information about the content of bug reports.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Monorail | <2018-04-04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10099 is considered a medium severity vulnerability due to its potential impact on data confidentiality.
To fix CVE-2018-10099, update to a version of Google Monorail released after April 4, 2018.
CVE-2018-10099 is a Cross-Site Search (XS-Search) vulnerability related to CSRF in CSV downloads.
CVE-2018-10099 affects all versions of Google Monorail prior to 2018-04-04.
CVE-2018-10099 could potentially expose sensitive information about the content of bug reports.