« Volver al listado

CVE-2020-8923

Estado: ModificadaMedia (6.1)—

An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an attacker leveraging DOM Clobbering techniques to skip the sanitization and inject custom html/javascript (XSS). Mitigation: update your Dart SDK to 2.7.2, and 2.8.0-dev.17.0 for the dev version. If you cannot update, we recommend you review the way you use the affected APIs, and pay special attention to cases where user-provided data is used to populate DOM nodes. Consider using Element.innerText or Node.text to populate DOM elements.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-8923",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-coordination@google.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve-coordination@google.com",
      "affectedData": [
        {
          "vendor": "Google",
          "product": "Dart SDK",
          "versions": [
            {
              "status": "affected",
              "version": "stable",
              "versionType": "custom",
              "lessThanOrEqual": "2.7.1"
            },
            {
              "status": "affected",
              "version": "dev",
              "versionType": "custom",
              "lessThanOrEqual": "2.8.0-dev.16.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-03-26T12:15:12.217",
  "references": [
    {
      "url": "https://github.com/dart-lang/sdk/security/advisories/GHSA-hfq3-v9pv-p627",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://github.com/dart-lang/sdk/security/advisories/GHSA-hfq3-v9pv-p627",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-coordination@google.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an attacker leveraging DOM Clobbering techniques to skip the sanitization and inject custom html/javascript (XSS). Mitigation: update your Dart SDK to 2.7.2, and 2.8.0-dev.17.0 for the dev version. If you cannot update, we recommend you review the way you use the affected APIs, and pay special attention to cases where user-provided data is used to populate DOM nodes. Consider using Element.innerText or Node.text to populate DOM elements."
    },
    {
      "lang": "es",
      "value": "Un saneamiento HTML inapropiado en Dart versiones hasta 2.7.1 y las versiones dev 2.8.0-dev.16.0, permite a un atacante aprovechar las técnicas DOM Clobbering para omitir el saneamiento e inyectar html/javascript personalizado (XSS). Mitigación: actualizar su Dart SDK a versión 2.7.2 y a versión 2.8.0-dev.17.0 para la versión de desarrollo. Si no puede actualizar, le recomendamos que revise la manera en que usa las API afectadas y preste especial atención a los casos en los que los datos provistos por el usuario son utilizados para completar los nodos DOM. Considere usar Element.innerText o Node.text para llenar los elementos DOM."
    }
  ],
  "lastModified": "2026-06-17T03:27:11.160",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dart:dart_software_development_kit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "245EA6E1-858A-4EE0-8783-D6FC91C304F8",
              "versionEndExcluding": "2.7.2"
            },
            {
              "criteria": "cpe:2.3:a:dart:dart_software_development_kit:2.8.0:dev0.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C378984-C1E4-4541-AF8F-F00950C27297"
            },
            {
              "criteria": "cpe:2.3:a:dart:dart_software_development_kit:2.8.0:dev1.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B7D246F3-B3A0-497A-8C5F-5ADC9735D3D9"
            },
            {
              "criteria": "cpe:2.3:a:dart:dart_software_development_kit:2.8.0:dev10.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "932257F3-0AC1-4181-A6E2-F05AA5458F0B"
            },
            {
              "criteria": "cpe:2.3:a:dart:dart_software_development_kit:2.8.0:dev11.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3604B788-12F5-4464-9264-D480A1CFEB4F"
            },
            {
              "criteria": "cpe:2.3:a:dart:dart_software_development_kit:2.8.0:dev12.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5DCBC478-7046-44DF-ADF0-03D45E1A5C69"
            },
            {
              "criteria": "cpe:2.3:a:dart:dart_software_development_kit:2.8.0:dev13.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85F43007-8E34-4B52-9D9D-4EBDF0C99BD5"
            },
            {
              "criteria": "cpe:2.3:a:dart:dart_software_development_kit:2.8.0:dev14.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E37CB132-888D-4D20-871D-50BC29FF497C"
            },
            {
              "criteria": "cpe:2.3:a:dart:dart_software_development_kit:2.8.0:dev15.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CDAAE2E2-2BD9-41B8-903B-FA113B3074F0"
            },
            {
              "criteria": "cpe:2.3:a:dart:dart_software_development_kit:2.8.0:dev16.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0163439B-633A-475D-B7C3-56EBEDFA1A60"
            },
            {
              "criteria": "cpe:2.3:a:dart:dart_software_development_kit:2.8.0:dev2.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33E498C7-7A01-4F27-ADED-679ADC702DA5"
            },
            {
              "criteria": "cpe:2.3:a:dart:dart_software_development_kit:2.8.0:dev3.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E2FE06D-3A1F-4051-865F-29DDD4CC4ADB"
            },
            {
              "criteria": "cpe:2.3:a:dart:dart_software_development_kit:2.8.0:dev4.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB27262C-0156-47AE-B9EF-CFA1748AF9BA"
            },
            {
              "criteria": "cpe:2.3:a:dart:dart_software_development_kit:2.8.0:dev5.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24BCF25D-D5F5-49A1-9209-3C2F88A10516"
            },
            {
              "criteria": "cpe:2.3:a:dart:dart_software_development_kit:2.8.0:dev6.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2417EDC0-751B-4DE9-A61B-885175855D58"
            },
            {
              "criteria": "cpe:2.3:a:dart:dart_software_development_kit:2.8.0:dev7.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE211D61-1029-4987-8B1C-C1791FEF53D4"
            },
            {
              "criteria": "cpe:2.3:a:dart:dart_software_development_kit:2.8.0:dev8.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B7066A39-DD04-47EB-9F67-DC4A7285B864"
            },
            {
              "criteria": "cpe:2.3:a:dart:dart_software_development_kit:2.8.0:dev9.0:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71C09C17-1558-401E-AA73-F4B1C2BAD816"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-coordination@google.com"
}