http
A composable API for making HTTP requests in Dart.
Activity
- Latest release
- 10mo ago
- Total releases
- 130
- Cadence
- ~2 months
- Last 12 months
- 1
Reach
- Stars
- 1.1k
Details
- First release
- Nov 30, 2012
| Version | Released | |
|---|---|---|
1.6.0
minor
| ||
1.5.0
minor
| ||
1.5.0-beta.2
pre
| ||
1.5.0-beta
pre
| ||
1.4.0
minor
| ||
1.3.0
minor
| ||
1.2.2
patch
| ||
1.2.1
patch
| ||
1.2.0
minor
| ||
1.1.2
patch
| ||
1.1.1
patch
| ||
1.1.0
minor
| ||
1.0.0
major
| ||
0.13.6
patch
| ||
0.13.5
patch
| ||
0.13.4
patch
| ||
0.13.3
patch
| ||
0.13.2
patch
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.13.1
patch
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.13.0
minor
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.13.0-nullsafety.0
pre
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.12.2
patch
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.12.1
patch
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.12.0+4
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.12.0+3
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.12.0+2
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.12.0+1
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.12.0
minor
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.3+17
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.3+16
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.3+15
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.3+14
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.3+13
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.3+12
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.3+11
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.3+9
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.3+8
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.3+7
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.3+6
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.3+5
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.3+4
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.3+3
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.3+2
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.3+1
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.3
patch
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.2
patch
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.1+3
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.1+1
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.1
patch
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.11.0+1
unknown
1 CVE
CVE-2020-35669
GHSA-4rgh-jx4f-qfcq
May 24, 2022
http before 0.13.3 vulnerable to header injection
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
An issue was discovered in the http package before 0.13.3 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request via HTTP header injection. This issue has been addressed in commit abb2bb182 by validating request methods. Affected versions
0.10.0
0.11.0
0.11.0+1
0.11.1
0.11.1+1
0.11.1+3
0.11.2
0.11.3
0.11.3+1
0.11.3+11
0.11.3+12
0.11.3+13
+ 101 more Show less
0.11.3+14
0.11.3+15
0.11.3+16
0.11.3+17
0.11.3+2
0.11.3+3
0.11.3+4
0.11.3+5
0.11.3+6
0.11.3+7
0.11.3+8
0.11.3+9
0.12.0
0.12.0+1
0.12.0+2
0.12.0+3
0.12.0+4
0.12.1
0.12.2
0.13.0
0.13.0-nullsafety.0
0.13.1
0.13.2
0.2.10+1
0.2.7+0
0.2.8+2
0.2.9+7
0.3.1+1
0.3.2
0.3.4
0.3.5+1
0.3.7+6
0.4.0
0.4.1
0.4.2
0.4.3+1
0.4.4+4
0.4.5+1
0.4.7+1
0.5.0+1
0.5.1
0.5.11+1
0.5.12
0.5.13
0.5.14+1
0.5.14+3
0.5.15
0.5.16
0.5.17
0.5.20
0.5.4
0.5.5
0.5.6
0.5.7
0.5.9
0.6.1
0.6.11
0.6.12
0.6.13
0.6.14
0.6.15+2
0.6.15+3
0.6.17
0.6.17+2
0.6.19
0.6.2
0.6.20+1
0.6.21+3
0.6.3+1
0.6.5
0.6.6
0.6.8
0.6.9
0.6.9+2
0.7.0
0.7.1
0.7.2
0.7.2+1
0.7.3+1
0.7.4
0.7.5
0.7.6
0.7.6+4
0.8.0
0.8.1
0.8.10
0.8.10+3
0.8.10+4
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.8.9
0.9.0
0.9.1
0.9.2
0.9.2+1
0.9.2+3
Fixed in
0.13.3
References
Updated Nov 08, 2023 · Source: OSV.dev |