CVE-2022-3474 Information
Oct 27, 2022
cve
Description
A bad credential handling in the remote assets API for Bazel versions prior to 5.3.2 and 4.2.3 sends all user-provided credentials instead of only the required ones for the requests. We recommend upgrading to versions later than or equal to 5.3.2 or 4.2.3.
Reference
https://github.com/bazelbuild/bazel/security/advisories/GHSA-mxr8-q875-rhwq
Share on: