Skip to content

azure-pipelines-tasks-azure-arm-rest Task is not using latest version of OpenSSL (3.4.0) #415

@ykbajpai

Description

@ykbajpai

We have received vulnerable issue for azure pipeline tasks on our build VM for following tasks where all issues are reported for open ssl, please upgrade it to latest version of open ssl in azure task.

The technology OpenSSL version 1.0.2k associated with the path \_tasks\AzureAppServiceManage_f045e430-8704-11e6-968f-e717e6411619\0.247.1\node_modules\azure-pipelines-tasks-azure-arm-rest\openssl\openssl.exe has been End-of-Life since 2019-12-20.

End-of-Life versions of technologies have no further official support by the vendor and thus no security patches. Furthermore, newly discovered vulnerabilities are not reported. Thus, such technologies pose a threat that is both unknown and will not be fixed.

Below are the tasks 👍
_tasks\AzureAppServiceSettings_3eeea460-bffa-11e9-9cb5-2a2ae2dbcce4\1.247.1\node_modules\azure-pipelines-tasks-azure-arm-rest\openssl
_tasks\AzureRmWebAppDeployment_497d490f-eea7-4f2b-ab94-48d9c1acdcb1\4.247.1\node_modules\azure-pipelines-tasks-azure-arm-rest\openssl
_tasks\AzureAppServiceManage_f045e430-8704-11e6-968f-e717e6411619\0.247.1\node_modules\azure-pipelines-tasks-azure-arm-rest\openssl

Please upgrade OpenSSL to latest as this end of life today.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions