VulnerabilityModified
CVE-2021-22567
An attacker could embed a source that is invisible to a code reviewer that modifies the behavior of a program in unexpected ways.
LOW 3.5EPSS 0.60%
Does this matter?
Lower severity and a low EPSS score (0.60%). Track it; it rarely justifies an emergency change on its own.
Description
Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign. An attacker could embed a source that is invisible to a code reviewer that modifies the behavior of a program in unexpected ways.
- CVSS 3.1
- 3.5 LOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
- EPSS
- 0.60% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- dart/dart software development kit
- Source
- cve-coordination@google.com
References
- https://github.com/dart-lang/sdk/blob/main/CHANGELOG.mdRelease Notes, Third Party Advisory
- https://github.com/dart-lang/sdk/commit/52519ea8eb4780c468c4c2ed00e7c8046ccfed41Patch, Third Party Advisory
- https://github.com/dart-lang/sdk/blob/main/CHANGELOG.mdRelease Notes, Third Party Advisory
- https://github.com/dart-lang/sdk/commit/52519ea8eb4780c468c4c2ed00e7c8046ccfed41Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.