Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-0451

Опубликовано: 18 фев. 2022
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient handles redirection logic. If a request is sent to example.com with authorization header and it redirects to an attackers site, they might not expect attacker site to receive authorization header. We recommend updating the Dart SDK to version 2.16.0 or beyond.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dart:dart_software_development_kit:*:*:*:*:*:*:*:*
Версия до 2.16.0 (исключая)

EPSS

Процентиль: 38%
0.00164
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-305
CWE-863

EPSS

Процентиль: 38%
0.00164
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-305
CWE-863