Описание
Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder.
Ссылки
- Broken LinkThird Party Advisory
- Broken LinkThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.211.1 (включая)
cpe:2.3:a:chocolatey:chocolatey_azure-pipelines-agent:*:*:*:*:*:*:*:*
EPSS
Процентиль: 30%
0.00114
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-732
CWE-732
Связанные уязвимости
CVSS3: 4.3
github
около 3 лет назад
Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder.
EPSS
Процентиль: 30%
0.00114
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-732
CWE-732