MEDIUM
An issue was discovered in the http package through 0.12.2 for Dart
Published Dec 24, 2020
6.1
MEDIUMCVSS 3.1
EPSS 2.15%
Description
An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-2440 Advisory
- https://github.com/advisories/GHSA-4rgh-jx4f-qfcq Advisory
- https://github.com/dart-lang/http/blob/master/CHANGELOG.md#0133 x_refsource_MISCBroken LinkRelease NotesThird Party Advisory
- https://github.com/dart-lang/http/commit/abb2bb182fbd7f03aafd1f889b902d7b3bdb8769
- https://github.com/dart-lang/http/issues/511 x_refsource_MISCExploitPatchThird Party Advisory
- https://github.com/dart-lang/http/pull/512
- https://nvd.nist.gov/vuln/detail/CVE-2020-35669
- https://pub.dev/packages/http/changelog#0133
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-2440 | Advisory | |
| https://github.com/advisories/GHSA-4rgh-jx4f-qfcq | Advisory | |
| https://github.com/dart-lang/http/blob/master/CHANGELOG.md#0133 | x_refsource_MISCBroken LinkRelease NotesThird Party Advisory | |
| https://github.com/dart-lang/http/commit/abb2bb182fbd7f03aafd1f889b902d7b3bdb8769 | ||
| https://github.com/dart-lang/http/issues/511 | x_refsource_MISCExploitPatchThird Party Advisory | |
| https://github.com/dart-lang/http/pull/512 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2020-35669 | ||
| https://pub.dev/packages/http/changelog#0133 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 24, 2020
Updated Aug 4, 2024
Reserved Dec 24, 2020
Link CVE-2020-35669
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-2440 GHSA-4RGH-JX4F-QFCQ Assigner mitre
Published Dec 24, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2022-2440