First published: Tue Nov 29 2022(Updated: )
Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Azure Pipelines Agent | <=2.211.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45306 has a critical severity due to the insecure permissions allowing unauthorized write access.
To fix CVE-2022-45306, you should update the Chocolatey Azure-Pipelines-Agent package to version 2.211.2 or later.
The consequences of CVE-2022-45306 include potential unauthorized changes to the C:\agent directory, leading to security breaches.
Any user with access to the Authenticated Users group is affected by CVE-2022-45306, as they gain write privileges on the vulnerable directory.
Chocolatey Azure-Pipelines-Agent versions v2.211.1 and below are vulnerable to CVE-2022-45306.