Skip to content

[Question]: openssl 1.0.2 vulnerability is being reported #20802

Open
@AshishDadhich4h2

Description

Task name

AzurePowerShell and AzureKeyVault

Task version

5.247.5 and 2.235.1

Environment type (Please select at least one enviroment where you face this issue)

  • Self-Hosted
  • Microsoft Hosted
  • VMSS Pool
  • Container

Azure DevOps Server type

dev.azure.com (formerly visualstudio.com)

Azure DevOps Server Version (if applicable)

No response

Operation system

Windows

Question

This is installing openssl 1.0.2 (last updated 12/2019) and has known vulnerabilities.
OpenSSL has strongly recommended upgrading vulnerable versions to the latest patch of 3.0.7 to address the potential impact of the vulnerabilities.

Is any plan to update openssl version?

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions