Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-5899

Опубликовано: 18 июн. 2024
Источник: nvd
CVSS3: 3.3
EPSS Низкий

Описание

When Bazel Plugin in intellij imports a project (either using "import project" or "Auto import") the dialog for trusting the project is not displayed. This comes from the fact that both call the method ProjectBuilder.createProject which then calls ProjectManager.getInstance().createProject. This method, as its name suggests is intended to create a new project, not to import an existing one.  We recommend upgrading to version 2024.06.04.0.2 or beyond for the IntelliJ, CLion and Android Studio Bazel plugins.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:google:bazel_for_android_studio:*:*:*:*:*:*:*:*
Версия до 2024.06.04.0.2 (исключая)
cpe:2.3:a:google:bazel_for_clion:*:*:*:*:*:*:*:*
Версия до 2024.06.04.0.2 (исключая)
cpe:2.3:a:google:bazel_for_intellij:*:*:*:*:*:*:*:*
Версия до 2024.06.04.0.2 (исключая)

EPSS

Процентиль: 16%
0.00052
Низкий

3.3 Low

CVSS3

Дефекты

CWE-862
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 3.3
github
больше 1 года назад

When Bazel Plugin in intellij imports a project (either using "import project" or "Auto import") the dialog for trusting the project is not displayed. This comes from the fact that both call the method ProjectBuilder.createProject which then calls ProjectManager.getInstance().createProject. This method, as its name suggests is intended to create a new project, not to import an existing one.  We recommend upgrading to version 2024.06.04.0.2 or beyond for the IntelliJ, CLion and Android Studio Bazel plugins.

EPSS

Процентиль: 16%
0.00052
Низкий

3.3 Low

CVSS3

Дефекты

CWE-862
NVD-CWE-noinfo