CVE-2021-22568
Dashboard / Vulnerabilities / CVE-2021-22568
Summary:
Details: When using the dart pub publish command to publish a package to a third-party package server, the request would be authenticated with an oauth2 access_token that is valid for publishing on pub.dev. Using these obtained credentials, an attacker can impersonate the user on pub.dev. We recommend upgrading past https://github.com/dart-lang/sdk/commit/d787e78d21e12ec1ef712d229940b1172aafcdf8 or beyond version 2.15.0
References: https://github.com/dart-lang/sdk/security/advisories/GHSA-r32f-vhjp-qhj7, https://github.com/dart-lang/sdk/blob/main/CHANGELOG.md, https://github.com/dart-lang/sdk/commit/d787e78d21e12ec1ef712d229940b1172aafcdf8
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
2.14.4
2.14.3
2.14.2
2.14.1
2.14.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
