Severity |
|
Remote |
|
Type |
- |
Unknown |
+ |
Content spoofing |
|
Description |
+ |
A security issue has been found in the Dart Core SDK before version 2.15.0. Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors and code-review tools. Exploiting this an attacker could embed source that is invisible to a code reviewer but that modifies the behavior of a program in unexpected ways. This vulnerability impacts all projects that allow Dart source contributions. |
|
References |
+ |
https://github.com/dart-lang/sdk/security/advisories/GHSA-8pcp-6qc9-rqmv |
+ |
https://github.com/dart-lang/sdk/issues/47611 |
+ |
https://github.com/dart-lang/sdk/commit/b403d4bf73542b974fb85bfbe58c7e2136b8318d |
|
Notes |
|