CVE Vulnerabilities

CVE-2022-3474

Insufficiently Protected Credentials

Published: Oct 26, 2022 | Modified: Oct 28, 2022
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A bad credential handling in the remote assets API for Bazel versions prior to 5.3.2 and 4.2.3 sends all user-provided credentials instead of only the required ones for the requests. We recommend upgrading to versions later than or equal to 5.3.2 or 4.2.3.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Bazel Google 3.1.0 (including) 4.2.3 (excluding)
Bazel Google 5.0.0 (including) 5.3.2 (excluding)

Potential Mitigations

References