ZeroHour

CVE-2020-35669

PoC
CVSS 3.1
6.1 medium
EPSS
2%p81
Published
()
Modified
Description

An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request.

Vendors
dart
Products
http
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.