<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Bazel</title>
  <link>https://cvedaily.com/pages/tags/bazel.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/bazel.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Bazel</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:08 +0000</lastBuildDate>
  <item>
    <title>[Low] CVE-2024-5899 – When Bazel Plugin in intellij imports a project (either using "import project" o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5899</guid>
    <pubDate>Tue, 18 Jun 2024 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-5899</strong></p>
  <p>When Bazel Plugin in intellij imports a project (either using "import project" or "Auto import") the dialog for trusting the project is not displayed. This comes from the fact that both call the method ProjectBuilder.createProject which then calls ProjectManager.getInstance().createProject. This method, as its name suggests is intended to create a new project, not to import an existing one.  We r…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-3474 – A bad credential handling in the remote assets API for Bazel versions prior to 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3474</guid>
    <pubDate>Wed, 26 Oct 2022 19:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-3474</strong></p>
  <p>A bad credential handling in the remote assets API for Bazel versions prior to 5.3.2 and 4.2.3 sends all user-provided credentials instead of only the required ones for the requests. We recommend upgrading to versions later than or equal to 5.3.2 or 4.2.3.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22539 – An attacker can place a crafted JSON config file into the project folder pointin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22539</guid>
    <pubDate>Fri, 16 Apr 2021 11:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22539</strong></p>
  <p>An attacker can place a crafted JSON config file into the project folder pointing to a custom executable. VScode-bazel allows the workspace path to lint *.bzl files to be set via this config file. As such the attacker is able to execute any executable on the system through vscode-bazel. We recommend upgrading to version 0.4.1 or above.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22539">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
