Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Question]: Agent install being flagged for CVE-2024-21907 #4593

Closed
1 of 4 tasks
MDavisF opened this issue Jan 9, 2024 · 9 comments
Closed
1 of 4 tasks

[Question]: Agent install being flagged for CVE-2024-21907 #4593

MDavisF opened this issue Jan 9, 2024 · 9 comments
Assignees

Comments

@MDavisF
Copy link

MDavisF commented Jan 9, 2024

Describe your question

Hi all,

My company is using Wiz to scan various virtual machine resources, and my team is running some Windows build agents through Azure DevOps.

Agent version - 3.230.0

The agent and work directories for each agent service are being flagged by Wiz due to having older verisons of Newtonsoft.Json
(9.0.1 and 10.0.3) - I have tested upgrading to agent version 3.232.1 however that appears to still be using the same library references.

See vulnerability reference here: CVE-2024-21907

A specific example of one of these flags:

image

Is there currently a PR in progress to address this, or otherwise an ETA for resolution? Any input would be appreciated.

Thank you kindly,

Matthew

Versions

Azure DevOps Agent version 3.230.0 / Windows Server 2019 (for build agents)

Environment type (Please select at least one enviroment where you face this issue)

  • Self-Hosted
  • Microsoft Hosted
  • VMSS Pool
  • Container

Azure DevOps Server type

Azure DevOps Server (Please specify exact version in the textbox below)

Operation system

Windows Server 2019

Version controll system

No response

Azure DevOps Server Version (if applicable)

Azure DevOps Server 2022.1

@clint-NGH
Copy link

I am having the same issue. Any update?

@martin-toman martin-toman self-assigned this Apr 18, 2024
@martin-toman
Copy link
Contributor

martin-toman commented May 29, 2024

Thank you for reporting this!
Internal bug #: 2172569.

Issue summary:
The TF.exe that is downloaded by the Agent, which comes with the Newtonsoft.Json dll, was built long time ago.
We need to create a Continuous Delivery pipeline for TF.exe to ensure it is regularly updated with the latest dependencies.

ETA of Resolution: July.

@AkechiShiro
Copy link

Any news to share @martin-toman ?

@martin-toman
Copy link
Contributor

#4950

@martin-toman
Copy link
Contributor

Safer approach: #4955

@lfpcabral
Copy link

Does anyone know when MS should be releasing a new pipeline agent with the updated tf?

@Zero-TrustSolutions
Copy link

any updates?

@aleksandrlevochkin
Copy link
Contributor

This fix should be available in v3.244.1

@aleksandrlevochkin
Copy link
Contributor

I'm closing this issue as the fix has been rolled out. Please feel free to re-open it if you still experience this issue

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

8 participants