VDB

CVE-2022-3095

CVE-2022-3095 PUBLISHED CVSS 9.800000190734863 CRITICAL

The implementation of backslash parsing in the Dart URI class for versions prior to 2.18 and Flutter versions prior to 3.30 differs from the WhatWG URL standards. Dart uses the RFC 3986 syntax, which creates incompatibilities with the '\' characters in URIs, which can lead to auth bypass in webapps interpreting URIs. We recommend updating Dart or Flutter to mitigate the issue.

EPSS 0.93% · 59.1th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.93%
59.1th percentile

Affected Products

VendorProductVersions
flutterflutter0
dartdart_software_development_kit0
Google LLCDartstable, *

Timeline

  • Oct 27, 2022 CVE Published
  • Oct 28, 2022 EPSS Score
  • Dec 11, 2022 EPSS Score
  • Jan 24, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 9, 2023 EPSS Score
  • Apr 21, 2023 EPSS Score
  • Jun 4, 2023 EPSS Score
  • Jul 18, 2023 EPSS Score
  • Oct 14, 2023 EPSS Score
  • Nov 27, 2023 EPSS Score
  • Jan 10, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›