CVE-2020-35669
MEDIUM 6.1EPSS 2.2%
An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request.
- CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N - EPSS
- 2.15% chance of exploitation in the next 30 days, 81th percentile
- Published
- 2020-12-24
- Updated
- 2024-08-04
Proof-of-concept exploits (1)
- n0npax/CVE-2020-356691★ · 2021-01-01