Описание
An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request.
Ссылки
- Broken LinkRelease NotesThird Party Advisory
- ExploitPatchThird Party Advisory
- Broken LinkRelease NotesThird Party Advisory
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.12.2 (включая)
cpe:2.3:a:dart:http:*:*:*:*:*:dart:*:*
EPSS
Процентиль: 96%
0.25314
Средний
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-74
Связанные уязвимости
CVSS3: 6.1
github
больше 3 лет назад
http before 0.13.3 vulnerable to header injection
EPSS
Процентиль: 96%
0.25314
Средний
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-74