Detailedseverity: MediumDraft
CAPEC-462Cross-Domain Search Timing
Abstraction
Detailed
Status
Draft
Severity
Medium
Description
An attacker initiates cross domain HTTP / GET requests and times the server responses. The timing of these responses may leak important information on what is happening on the server. Browser's same origin policy prevents the attacker from directly reading the server responses (in the absence of any other weaknesses), but does not prevent the attacker from timing the responses to requests that the attacker issued cross domain.
Related weaknesses· 3
Related attack patterns· 1
Exploits3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Covert Timing Channelcwe-385 | 100% | live |
| Weakness | Observable Timing Discrepancycwe-208 | 100% | live |
| Weakness | Cross-Site Request Forgery (CSRF)cwe-352 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.