CVE-2020-8923
Summary
| CVE | CVE-2020-8923 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-26 12:15:00 UTC |
| Updated | 2020-03-31 19:52:00 UTC |
| Description | An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an attacker leveraging DOM Clobbering techniques to skip the sanitization and inject custom html/javascript (XSS). Mitigation: update your Dart SDK to 2.7.2, and 2.8.0-dev.17.0 for the dev version. If you cannot update, we recommend you review the way you use the affected APIs, and pay special attention to cases where user-provided data is used to populate DOM nodes. Consider using Element.innerText or Node.text to populate DOM elements. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dart | Dart Software Development Kit | All | All | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev0.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev1.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev10.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev11.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev12.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev13.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev14.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev15.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev16.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev2.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev3.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev4.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev5.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev6.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev7.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev8.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev9.0 | All | All |
| Application | Dart | Dart Software Development Kit | All | All | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev0.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev1.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev10.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev11.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev12.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev13.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev14.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev15.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev16.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev2.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev3.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev4.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev5.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev6.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev7.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev8.0 | All | All |
| Application | Dart | Dart Software Development Kit | 2.8.0 | dev9.0 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| XSS vulnerability in dart:html · Advisory · dart-lang/sdk · GitHub | CONFIRM | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Vincenzo di Cicco
There are currently no legacy QID mappings associated with this CVE.