CVE-2021-22567
Dashboard / Vulnerabilities / CVE-2021-22567
CVE-2021-22567
Published: 5 Jan 2022Last Modified: 9 Jul 2026
Summary:
Details: Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign. An attacker could embed a source that is invisible to a code reviewer that modifies the behavior of a program in unexpected ways.
References: https://github.com/dart-lang/sdk/blob/main/CHANGELOG.md, https://github.com/dart-lang/sdk/commit/52519ea8eb4780c468c4c2ed00e7c8046ccfed41
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
2.14.4
2.14.3
2.14.2
2.14.1
2.14.0-377.8.beta
2.14.0
2.14.0-377.7.beta
2.14.0-377.4.beta
2.14.0-377.1.beta
2.14.0-301.2.beta
2.14.0-188.5.beta
2.14.0-188.3.beta
2.14.0-188.1.beta
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
