Vulnerability Note VU#571584
Google Gmail cross-site request forgery vulnerability
Overview
According to public reports, Google Gmail contained a cross-site request forgery (XSRF) vulnerability that allowed attackers to create email filters that could forward mail and attachments to arbitrary email addresses.
Description
Google Gmail is a web-based mail service. Gmail provides support for email filters that allow users to sort and forward mail. According to a report on the GNUCITIZEN site, Gmail contained a cross-site request forgery (XSRF) vulnerability that allowed attackers to create mail filters and forward mail to arbitrary email addresses. To exploit this vulnerability, an attacker would have had to convince a user to click or open a specially crafted hyperlink while the user was logged into their Gmail account. The hyperlink would have contained an http POST request that created the mail filter. |
Impact
A remote attacker could have collected email addresses, emails, and attachments from a user's Gmail account. |
Solution
According to publicly available reports, Google has addressed this vulnerability. |
The following workarounds may partially mitigate future cross-site scripting (XSS) and XSRF vulnerabilities:
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Affected | - | 01 Oct 2007 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/
- http://www.w3.org/Protocols/rfc2616/rfc2616-sec9.html
- http://mail.google.com/support/bin/answer.py?hl=en&answer=13273
- http://noscript.net/
- http://www.cert.org/homeusers/email_postcard.html
Credit
Information about this vulnerability was disclosed on the GNUCITIZEN web site.
This document was written by Ryan Giobbi.
Other Information
- CVE IDs: Unknown
- Date Public: 25 Sep 2007
- Date First Published: 01 Oct 2007
- Date Last Updated: 12 Feb 2008
- Severity Metric: 0.79
- Document Revision: 19
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.