GHSA-jwpw-q68h-r678

Source
https://github.com/advisories/GHSA-jwpw-q68h-r678
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jwpw-q68h-r678/GHSA-jwpw-q68h-r678.json
Withdrawn
2023-10-05T17:32:48Z
Published
2022-05-24T17:47:44Z
Modified
2024-02-16T08:16:01.751955Z
Details

Duplicate advisory

This advisory has been withdrawn because it is a duplicate of GHSA-9324-jv53-9cc8. This link is maintained to preserve external references.

Original Description

The dio package prior to 5.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669.

References

Affected packages

Pub / dio

Package

Name
dio

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
5.0.0

Affected versions

0.*

0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8

1.*

1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17

2.*

2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.22
2.0.23
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.2.0
2.2.1
2.2.2

3.*

3.0.0-dev.1
3.0.0
3.0.1
3.0.2-dev.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8-dev.1
3.0.8
3.0.9
3.0.10

4.*

4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.0
4.0.1
4.0.2-beta1
4.0.2
4.0.3
4.0.4
4.0.5-beta1
4.0.5
4.0.6