Описание
Duplicate Advisory: Improper Neutralization of CRLF Sequences in dio
Duplicate advisory
This advisory has been withdrawn because it is a duplicate of GHSA-9324-jv53-9cc8. This link is maintained to preserve external references.
Original Description
The dio package prior to 5.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669.
Пакеты
Наименование
dio
Затронутые версииВерсия исправления
< 5.0.0
5.0.0
7.5 High
CVSS3
Дефекты
CWE-74
CWE-88
CWE-93
7.5 High
CVSS3
Дефекты
CWE-74
CWE-88
CWE-93