CVE-2022-3474

MEDIUM

Google Bazel < 4.2.3 - Insufficiently Protected Credentials

Title source: rule

Description

A bad credential handling in the remote assets API for Bazel versions prior to 5.3.2 and 4.2.3 sends all user-provided credentials instead of only the required ones for the requests. We recommend upgrading to versions later than or equal to 5.3.2 or 4.2.3.

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 11.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-522
Status published

Affected Products (1)

google/bazel < 4.2.3

Timeline

Published Oct 26, 2022
Tracked Since Feb 18, 2026