Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Chocolatey Subscribe
Filtered by product Chocolatey Azure-pipelines-agent
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-45306 1 Chocolatey 1 Chocolatey Azure-pipelines-agent 2022-12-01 N/A 4.3 MEDIUM
Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder.