Vulnerabilities
Vulnerable Software
Google:  >> Bazel  Security Vulnerabilities
A bad credential handling in the remote assets API for Bazel versions prior to 5.3.2 and 4.2.3 sends all user-provided credentials instead of only the required ones for the requests. We recommend upgrading to versions later than or equal to 5.3.2 or 4.2.3.
CVSS Score
4.3
EPSS Score
0.0
Published
2022-10-26
An attacker can place a crafted JSON config file into the project folder pointing to a custom executable. VScode-bazel allows the workspace path to lint *.bzl files to be set via this config file. As such the attacker is able to execute any executable on the system through vscode-bazel. We recommend upgrading to version 0.4.1 or above.
CVSS Score
8.2
EPSS Score
0.001
Published
2021-04-16


Contact Us

Shodan ® - All rights reserved