Vulnerability CVE-2022-3474


Published: 2022-10-26

Description:
A bad credential handling in the remote assets API for Bazel versions prior to 5.3.2 and 4.2.3 sends all user-provided credentials instead of only the required ones for the requests. We recommend upgrading to versions later than or equal to 5.3.2 or 4.2.3.

 References:
https://github.com/bazelbuild/bazel/security/advisories/GHSA-mxr8-q875-rhwq

Copyright 2026, cxsecurity.com

 

Back to Top