CVE-2021-22567
Description
Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign. An attacker could embed a source that is invisible to a code reviewer that modifies the behavior of a program in unexpected ways.
- CVSS Version 3.1
- CVSS Version 2.0
nvd
CVE ID: CVE-2021-22567
Base Score: 3.5
Base Severity: LOW
Vector String:CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Impact Score: 1.4
Exploitability Score: 2.1
google
CVE ID: CVE-2021-22567
Base Score: 4.6
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Impact Score: 2.5
Exploitability Score: 2.1
nvd
CVE ID: CVE-2021-22567
Base Score: 3.5
Base Severity: LOW
Vector String:AV:N/AC:M/Au:S/C:N/I:P/A:N