An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request.
References
Link Resource
https://github.com/dart-lang/http/blob/master/CHANGELOG.md#0133 Broken Link Release Notes Third Party Advisory
https://github.com/dart-lang/http/issues/511 Exploit Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-12-24T02:05:30

Updated: 2021-06-28T11:45:29

Reserved: 2020-12-24T00:00:00


Link: CVE-2020-35669

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-12-24T03:15:12.530

Modified: 2022-07-19T11:02:05.260


Link: CVE-2020-35669

JSON object: View

cve-icon Redhat Information

No data.

CWE