updating busybox and rclone packages#1749
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
|
@kohinoorpalasara please read the following Contributor License Agreement(CLA). If you agree with the CLA, please reply with the following information.
Contributor License AgreementContribution License AgreementThis Contribution License Agreement (“Agreement”) is agreed to by the party signing below (“You”),
|
1 similar comment
|
@kohinoorpalasara please read the following Contributor License Agreement(CLA). If you agree with the CLA, please reply with the following information.
Contributor License AgreementContribution License AgreementThis Contribution License Agreement (“Agreement”) is agreed to by the party signing below (“You”),
|
The extension installs correctly; however, the container versions contain multiple critical security vulnerabilities that should be resolved as soon as possible.
Extension:
extensions/azuremonitor-metrics
Latest version available: 6.26.0-main-03-05-2026-701eb75f
CVE-2022-48174: BusyBox image version 1.36.1 (CVSS 9.8) is currently in use and should be upgraded to the latest 1.38.x version.
Extension 2:
extensions/azuremonitor-containers
Latest version available: 3.4.0-arc
CVE-2026-49980: Critical vulnerabilities have been identified in rclone (CVSS 9.8). The current version in use is rclone 1.69.3 and should be upgraded to version 1.74.x.