An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request.
References
Link | Resource |
---|---|
https://github.com/dart-lang/http/blob/master/CHANGELOG.md#0133 | Broken Link Release Notes Third Party Advisory |
https://github.com/dart-lang/http/issues/511 | Exploit Patch Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-12-24T02:05:30
Updated: 2021-06-28T11:45:29
Reserved: 2020-12-24T00:00:00
Link: CVE-2020-35669
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-12-24T03:15:12.530
Modified: 2022-07-19T11:02:05.260
Link: CVE-2020-35669
JSON object: View
Redhat Information
No data.
CWE