Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-9324-jv53-9cc8] dio vulnerable to CRLF injection with HTTP method string #4442

Closed

Conversation

hamde33
Copy link

@hamde33 hamde33 commented May 18, 2024

Updates

  • Affected products

Comments
Reference links:
CVE-2021-31402: This is the identifier of the vulnerability in the NVD database.
OSV - Open Source Vulnerabilities: Provides additional information about the vulnerability and the fix.
Issue #1752: Contains discussion and updates regarding the vulnerability and its fix in the project's GitHub repository.
Code commit:
Commit cfug/dio@927f79e: Describes the specific change made to fix the vulnerability and can be used as a reference for technical details.
Broader context:
You can search for other posts and discussions in the project's GitHub repository (such as Issue #1130) to get more context and information regarding the vulnerability and the fix.

@github
Copy link
Collaborator

github commented May 18, 2024

Hi there @AlexV525! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

@github-actions github-actions bot changed the base branch from main to hamde33/advisory-improvement-4442 May 18, 2024 05:53
@AlexV525
Copy link

What is the point of changing the modified date? What data does the field rely on?

@hamde33
Copy link
Author

hamde33 commented May 19, 2024

I executed the application on the Linux system and it worked without showing any error. The problem is that when installing the java project, I changed the version of the buckets, which led to a problem in the rest of the applications.

@hamde33 hamde33 closed this May 19, 2024
@github-actions github-actions bot deleted the hamde33-GHSA-9324-jv53-9cc8 branch May 19, 2024 05:46
@AlexV525
Copy link

Not sure if the CVE has anything to do with your applications. It's a Dart dependency.

@hamde33
Copy link
Author

hamde33 commented May 21, 2024

No, to fix the previous error, delete the cache file and restore the old version of the flutter

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants