Back to Database
Status published
Medium
CVE-2020-35669
An issue was discovered in the http package through 0.12.2...
Vulnerability Description
An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP request.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-35669
Credits & Attribution
No credits recorded in the NVD database.
References
More from dart
View All →CVE-2012-5389
NULL Pointer Dereference in PowerTCP WebServer for ActiveX 1.9.2 and...
High
7.5
CVE-2012-3819
Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used...
Medium
5
CVE-2008-4652
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications...
Critical
9.3
CVE-2007-2856
Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX...
Critical
9.3
CVE-2007-2855
Buffer overflow in a certain ActiveX control in DartZipLite.dll 1.8.5.3...
Critical
9.3
Affected Vendor
dart
View all reports →Affected Software
http
Vulnerable Versions:
0
Timeline
Official Publish:
December 24th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.