Azure Pipelines Agent
by Microsoft
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36437 | Hig | 0.57 | 8.8 | 0.02 | Nov 14, 2023 | Azure DevOps Server Remote Code Execution Vulnerability | ||
| CVE-2022-45306 | Med | 0.28 | 4.3 | 0.00 | Nov 29, 2022 | Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder. |
- risk 0.57cvss 8.8epss 0.02
Azure DevOps Server Remote Code Execution Vulnerability
- risk 0.28cvss 4.3epss 0.00
Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder.