CVE-2022-0451
Auth bypass in Dark SDK
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient handles redirection logic. If a request is sent to example.com with authorization header and it redirects to an attackers site, they might not expect attacker site to receive authorization header. We recommend updating the Dart SDK to version 2.16.0 or beyond.
Dart SDK contiene la biblioteca HTTPClient en dart:io que incluye encabezados de autorización cuando maneja redireccionamientos de origen cruzado. Estos encabezados pueden ser establecidas explícitamente y contienen información confidencial. Por fallo, HttpClient maneja la lógica de redirección. Si es enviado una petición a example.com con un encabezado de autorización y es redirigido a un sitio de atacantes, éstos podrían no esperar que el sitio del atacante reciba el encabezado de autorización. Recomendamos actualizar Dart SDK a versión 2.16.0 o superior
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-01 CVE Reserved
- 2022-02-18 CVE Published
- 2023-08-01 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-305: Authentication Bypass by Primary Weakness
- CWE-863: Incorrect Authorization
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://dart-review.googlesource.com/c/sdk/+/229947 | 2022-02-26 | |
https://github.com/dart-lang/sdk/commit/57db739be0ad4629079bfa94840064f615d35abc | 2022-02-26 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dart Search vendor "Dart" | Dart Software Development Kit Search vendor "Dart" for product "Dart Software Development Kit" | < 2.16.0 Search vendor "Dart" for product "Dart Software Development Kit" and version " < 2.16.0" | - |
Affected
|