Vulnerability Description
An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dart | Http | <= 0.12.2 |
Related Weaknesses (CWE)
References
- https://github.com/dart-lang/http/blob/master/CHANGELOG.md#0133Broken LinkRelease NotesThird Party Advisory
- https://github.com/dart-lang/http/issues/511ExploitPatchThird Party Advisory
- https://github.com/dart-lang/http/blob/master/CHANGELOG.md#0133Broken LinkRelease NotesThird Party Advisory
- https://github.com/dart-lang/http/issues/511ExploitPatchThird Party Advisory
FAQ
What is CVE-2020-35669?
CVE-2020-35669 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP ...
How severe is CVE-2020-35669?
CVE-2020-35669 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-35669?
Check the references section above for vendor advisories and patch information. Affected products include: Dart Http.