PT-2022-20404 · Google · Dart+1
Published
2022-10-27
·
Updated
2022-10-31
·
CVE-2022-3095
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dart versions prior to 2.18
Flutter versions prior to 3.30
Description
The implementation of backslash parsing in the Dart URI class differs from the WhatWG URL standards, as it uses the RFC 3986 syntax. This creates incompatibilities with the '' characters in URIs, which can lead to authentication bypass in web applications interpreting URIs.
Recommendations
For Dart versions prior to 2.18, update Dart to a version 2.18 or later to mitigate the issue.
For Flutter versions prior to 3.30, update Flutter to a version 3.30 or later to mitigate the issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dart
Flutter