The dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669.
References
Link | Resource |
---|---|
https://github.com/flutterchina/dio/issues/1130 | Exploit Issue Tracking Third Party Advisory |
https://github.com/flutterchina/dio/issues/1130 | Exploit Issue Tracking Third Party Advisory |
Configurations
History
21 Nov 2024, 06:05
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/flutterchina/dio/issues/1130 - Exploit, Issue Tracking, Third Party Advisory |
22 Mar 2023, 18:31
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:flutterchina:dio:*:*:*:*:*:dart:*:* |
03 May 2022, 16:04
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-74 |
Information
Published : 2021-04-15 19:15
Updated : 2024-11-21 06:05
NVD link : CVE-2021-31402
Mitre link : CVE-2021-31402
CVE.ORG link : CVE-2021-31402
JSON object : View
Products Affected
flutterchina
- dio
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')