GSD-2022-1002519

    Dashboard / Vulnerabilities / GSD-2022-1002519

    GSD-2022-1002519

    Published: 20 May 2022Last Modified: 14 Mar 2023

    Summary: Information Leakage in Analytics version curent as of 2022-05-19

    Details: In the Google Analytics admin web interface, current as of 2022-05-19 an information leakage exists in the Account Access Management and Property Access Management that can be used, resulting in an attacker determining if a Google-hosted email address is in fact a Google account or a google group, an alias to a user, or a user account. Additionally, if it is an alias Google will report the real email address associated with the alias. If it's an account it will add it (e.g. [email protected]). If it's a google group it will error out with: "Failed to register users" (e.g. [email protected]) If it is an alias, it will error out with "One of the email addresses entered is the alternate email address of a Google Account (e.g. [email protected]). The alternate email address has been changed to that account's primary email address." and it will change the email alias to the correct email.

    Affected packages

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GSD-2022-1002519 | CVE-DB