MEDIUM
Bazel leaks user credentials through the remote assets API
Published Oct 26, 2022
5.1
MEDIUMCVSS 4.0
EPSS 0.34%
Description
A bad credential handling in the remote assets API for Bazel versions prior to 5.3.2 and 4.2.3 sends all user-provided credentials instead of only the required ones for the requests. We recommend upgrading to versions later than or equal to 5.3.2 or 4.2.3.
Affected products
-
- Version 3.0.0StatusaffectedConstraints<3.7.2
- Version 4.0.0StatusaffectedConstraints<4.2.3
- Version 5.0.0StatusaffectedConstraints<5.3.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Google LLC | Bazel | unaffected |
|
-
- Version 3.0.0StatusaffectedConstraints<3.7.2
- Version 4.0.0StatusaffectedConstraints<4.2.3
- Version 5.0.0StatusaffectedConstraints<5.3.2
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
- https://github.com/bazelbuild/bazel/security/advisories/GHSA-mxr8-q875-rhwq Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/bazelbuild/bazel/security/advisories/GHSA-mxr8-q875-rhwq | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Google
Published Oct 26, 2022
Updated Aug 3, 2024
Reserved Oct 12, 2022
Link CVE-2022-3474
CISA Vulnrichment
Updated May 21, 2024