Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign. An attacker could embed a source that is invisible to a code reviewer that modifies the behavior of a program in unexpected ways.
References
Link | Resource |
---|---|
https://github.com/dart-lang/sdk/blob/main/CHANGELOG.md | Release Notes Third Party Advisory |
https://github.com/dart-lang/sdk/commit/52519ea8eb4780c468c4c2ed00e7c8046ccfed41 | Patch Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Google
Published: 2021-11-16T00:00:00
Updated: 2022-01-05T10:55:11
Reserved: 2021-01-05T00:00:00
Link: CVE-2021-22567
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-01-05T11:15:08.120
Modified: 2022-01-12T18:43:51.137
Link: CVE-2021-22567
JSON object: View
Redhat Information
No data.
CWE