Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Issue]: Agent install being flagged for CVE-2023-49210 #350

Open
marcelom2s opened this issue Jul 10, 2024 · 3 comments
Open

[Issue]: Agent install being flagged for CVE-2023-49210 #350

marcelom2s opened this issue Jul 10, 2024 · 3 comments

Comments

@marcelom2s
Copy link

Hi,

My company is using Wiz to scan various virtual machine resources, and we are running some Windows build agents through Azure DevOps.

Agent version - 3.241.0

The agent and work directories for each agent service are being flagged by Wiz due to having older version of openssl
(1.0.2l)

See vulnerability reference here: [https://github.com/advisories/GHSA-75w2-qv55-x7fv] ([
"https://gist.github.com/mcoimbra/b05a55a5760172dccaa0a827647ad63e",
"https://github.com/ossf/malicious-packages/tree/main/malicious/npm",
"https://www.npmjs.com/package/openssl"])

A specific example of one of these flags:

image

image

Is there currently a PR in progress to address this, or otherwise an ETA for resolution? Any input would be appreciated.

Agent version: 3.241.0
Azure DevOps Server type: dev.azure.com
Operation system: Windows 11
Version control system: GitHub

Best Regards,

Marcelo Calado

@marcelom2s
Copy link
Author

Anyone? Please let me know if there is anything else that I can provide.

@marcelom2s marcelom2s changed the title [Question]: Agent install being flagged for CVE-2023-49210 [Issue]: Agent install being flagged for CVE-2023-49210 Jul 22, 2024
@marcelom2s
Copy link
Author

Anyone? Please let me know if there is anything else that I can provide.

@marcelom2s
Copy link
Author

Anyone?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant