Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9324-jv53-9cc8

Опубликовано: 21 мар. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

dio vulnerable to CRLF injection with HTTP method string

Impact

The dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669.

Patches

The vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0.

Workarounds

Cherry-pick the commit to your own fork can resolves the vulberability too.

References

Пакеты

Наименование

dio

Затронутые версииВерсия исправления

< 5.0.0

5.0.0

EPSS

Процентиль: 57%
0.00353
Низкий

7.5 High

CVSS3

Дефекты

CWE-93

Связанные уязвимости

CVSS3: 7.5
nvd
почти 5 лет назад

The dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669.

EPSS

Процентиль: 57%
0.00353
Низкий

7.5 High

CVSS3

Дефекты

CWE-93