When using the dart pub publish command to publish a package to a third-party package server, the request would be authenticated with an oauth2 access_token that is valid for publishing on pub.dev. Using these obtained credentials, an attacker can impersonate the user on pub.dev. We recommend upgrading past https://github.com/dart-lang/sdk/commit/d787e78d21e12ec1ef712d229940b1172aafcdf8 or beyond version 2.15.0
Advisories
Source ID Title
EUVD EUVD EUVD-2021-9707 When using the dart pub publish command to publish a package to a third-party package server, the request would be authenticated with an oauth2 access_token that is valid for publishing on pub.dev. Using these obtained credentials, an attacker can impersonate the user on pub.dev. We recommend upgrading past https://github.com/dart-lang/sdk/commit/d787e78d21e12ec1ef712d229940b1172aafcdf8 or beyond version 2.15.0
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published:

Updated: 2024-08-03T18:44:14.137Z

Reserved: 2021-01-05T00:00:00

Link: CVE-2021-22568

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-09T17:15:07.567

Modified: 2024-11-21T05:50:20.490

Link: CVE-2021-22568

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses