First published: Tue Nov 20 2018(Updated: )
Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with a crafted groupby value) can be used to obtain sensitive information about the content of bug reports.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Monorail | <2018-06-07 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19335 is considered a moderate severity vulnerability due to its potential for sensitive information disclosure.
To fix CVE-2018-19335, ensure that you upgrade Google Monorail to a version released after June 7, 2018.
CVE-2018-19335 is a Cross-Site Search (XS-Search) vulnerability related to CSRF in CSV downloads.
Exploitation of CVE-2018-19335 could allow an attacker to gain unauthorized access to sensitive information contained in bug reports.
CVE-2018-19335 affects users of Google Monorail prior to the June 7, 2018 update.