ghsa-jwpw-q68h-r678
CVSS 7.5 osv_pub
Description
## Duplicate advisory This advisory has been withdrawn because it is a duplicate of GHSA-9324-jv53-9cc8. This link is maintained to preserve external references. ## Original Description The dio package prior to 5.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669.
Timeline
- Published
- unknown
- Last Modified
- unknown
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
Linked Vulnerabilities
No linked vulnerabilities found.
{
"affected": [
{
"database_specific": {
"source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jwpw-q68h-r678/GHSA-jwpw-q68h-r678.json"
},
"package": {
"ecosystem": "Pub",
"name": "dio",
"purl": "pkg:pub/dio"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "5.0.0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"0.0.1",
"0.0.10",
"0.0.11",
"0.0.12",
"0.0.13",
"0.0.14",
"0.0.2",
"0.0.3",
"0.0.4",
"0.0.5",
"0.0.6",
"0.0.7",
"0.0.8",
"0.0.9",
"0.1.1",
"0.1.2",
"0.1.3",
"0.1.4",
"0.1.5",
"0.1.6",
"0.1.7",
"0.1.8",
"1.0.0",
"1.0.1",
"1.0.10",
"1.0.11",
"1.0.12",
"1.0.13",
"1.0.14",
"1.0.15",
"1.0.16",
"1.0.17",
"1.0.2",
"1.0.3",
"1.0.4",
"1.0.5",
"1.0.6",
"1.0.7",
"1.0.8",
"1.0.9",
"2.0.0",
"2.0.1",
"2.0.10",
"2.0.11",
"2.0.12",
"2.0.13",
"2.0.14",
"2.0.15",
"2.0.16",
"2.0.17",
"2.0.18",
"2.0.19",
"2.0.2",
"2.0.20",
"2.0.21",
"2.0.22",
"2.0.23",
"2.0.3",
"2.0.4",
"2.0.5",
"2.0.6",
"2.0.7",
"2.0.8",
"2.0.9",
"2.1.0",
"2.1.1",
"2.1.10",
"2.1.11",
"2.1.12",
"2.1.13",
"2.1.14",
"2.1.15",
"2.1.16",
"2.1.2",
"2.1.3",
"2.1.4",
"2.1.5",
"2.1.6",
"2.1.7",
"2.1.8",
"2.1.9",
"2.2.0",
"2.2.1",
"2.2.2",
"3.0.0",
"3.0.0-dev.1",
"3.0.1",
"3.0.10",
"3.0.2",
"3.0.2-dev.1",
"3.0.3",
"3.0.4",
"3.0.5",
"3.0.6",
"3.0.7",
"3.0.8",
"3.0.8-dev.1",
"3.0.9",
"4.0.0",
"4.0.0-beta1",
"4.0.0-beta2",
"4.0.0-beta3",
"4.0.0-beta4",
"4.0.0-beta5",
"4.0.0-beta6",
"4.0.0-beta7",
"4.0.0-prev1",
"4.0.0-prev2",
"4.0.0-prev3",
"4.0.1",
"4.0.2",
"4.0.2-beta1",
"4.0.3",
"4.0.4",
"4.0.5",
"4.0.5-beta1",
"4.0.6"
]
}
],
"database_specific": {
"cwe_ids": [
"CWE-74",
"CWE-88",
"CWE-93"
],
"github_reviewed": true,
"github_reviewed_at": "2022-09-15T03:27:03Z",
"nvd_published_at": "2021-04-15T19:15:00Z",
"severity": "HIGH"
},
"details": "## Duplicate advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-9324-jv53-9cc8. This link is maintained to preserve external references.\n\n## Original Description\nThe dio package prior to 5.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669.",
"id": "GHSA-jwpw-q68h-r678",
"modified": "2024-11-29T05:40:27.940485Z",
"published": "2022-05-24T17:47:44Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-31402"
},
{
"type": "WEB",
"url": "https://github.com/cfug/dio/issues/1130"
},
{
"type": "WEB",
"url": "https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984"
},
{
"type": "PACKAGE",
"url": "https://github.com/cfug/dio"
},
{
"type": "WEB",
"url": "https://osv.dev/GHSA-jwpw-q68h-r678"
}
],
"schema_version": "1.9.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
],
"summary": "Duplicate Advisory: Improper Neutralization of CRLF Sequences in dio",
"withdrawn": "2023-10-05T17:32:48Z"
}