Google Bazel: vulnerabilidades y CVE
Google Bazel tiene 3 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE3
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-76226 | Media (6.8) | 0.29% | — | 19 ago 2026 | Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance. Attackers can execute arbitrary code by providing… |
| CVE-2022-3474 | Media (5.1) | 0.34% | — | 26 oct 2022 | A bad credential handling in the remote assets API for Bazel versions prior to 5.3.2 and 4.2.3 sends all user-provided credentials instead of only the required ones for the requests. We recommend upgrading to versions… |
| CVE-2021-22539 | Alta (7.8) | 0.31% | — | 16 abr 2021 | An attacker can place a crafted JSON config file into the project folder pointing to a custom executable. VScode-bazel allows the workspace path to lint *.bzl files to be set via this config file. As such the attacker… |
📰 Noticias relacionadas
- Alerta Google corrige tres vulnerabilidades en Chrome, una de ellas crítica en WebGL que permite escapar del sandbox
- Alerta Google corrige 95 vulnerabilidades en Chrome, 23 de ellas críticas, en su última actualización del canal estable
- Alerta Google corrige dos vulnerabilidades críticas en Cloud Application Integration sin requerir acción de los clientes