CVE-2018-19335
20.11.2018, 09:29
Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with a crafted groupby value) can be used to obtain sensitive information about the content of bug reports.
Vendor | Product | Version |
---|---|---|
monorail | 𝑥 < 2018-06-07 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration