Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance. Attackers can execute arbitrary cod…
Medium CVSS 6.3
Summary
Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance. Attackers can execute arbitrary code by providing malicious dependencies that are referenced in bazel mod deps calls, such as within ctx.execute statements.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/renovatebot/renovate/security/advisories/GHSA-5vjq-5jmg-39xq
- https://www.vulncheck.com/advisories/renovate-through-remote-code-execution-via-lockfilemaintenance
Timeline
- nvd_ingest NVD