CVE Database
/

CVE-2022-3474

Back to search

CVE-2022-3474

Published: Oct 26, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

A bad credential handling in the remote assets API for Bazel versions prior to 5.3.2 and 4.2.3 sends all user-provided credentials instead of only the required ones for the requests. We recommend upgrading to versions later than or equal to 5.3.2 or 4.2.3.

VendorProductVersions

Google LLC

Bazel

affected
5.0.0 - < 5.3.2
affected
4.0.0 - < 4.2.3
affected
3.0.0 - < 3.7.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2022-3474 - Security Vulnerability | QwikSec