Duplicate Advisory: Improper Neutralization of CRLF Sequences in dio
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Oct 5, 2023
Withdrawn
This advisory was withdrawn on Oct 5, 2023
Description
Published by the National Vulnerability Database
Apr 15, 2021
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Sep 15, 2022
Last updated
Oct 5, 2023
Withdrawn
Oct 5, 2023
Duplicate advisory
This advisory has been withdrawn because it is a duplicate of GHSA-9324-jv53-9cc8. This link is maintained to preserve external references.
Original Description
The dio package prior to 5.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669.
References