CVE-2022-3474

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
26/10/2022
Last modified:
21/05/2024

Description

A bad credential handling in the remote assets API for Bazel versions prior to 5.3.2 and 4.2.3 sends all user-provided credentials instead of only the required ones for the requests. We recommend upgrading to versions later than or equal to 5.3.2 or 4.2.3.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:bazel:*:*:*:*:*:visual_studio:*:* 3.1.0 (including) 4.2.3 (excluding)
cpe:2.3:a:google:bazel:*:*:*:*:*:visual_studio:*:* 5.0.0 (including) 5.3.2 (excluding)