OpenSSL version issue for self hosted agent

Scott Deverinne 0 Reputation points
2026-09-25T14:41:19.8566667+00:00

The OpenSSL version installed or imported as part of the Azure Function App Deploy task in a classic Azure DevOps pipeline on a self-hosted agent has been identified as a security vulnerability by one of our clients.

The client has performed a vulnerability scan and reported that the OpenSSL version being used is outdated and no longer meets their security requirements.

Azure DevOps
0 comments No comments

1 answer

Sort by: Oldest
  1. Taz 10,126 Reputation points MVP Volunteer Moderator
    2026-09-27T13:41:21.5233333+00:00

    Hi Scott,

    For a self-hosted agent, the AzureFunctionApp task runs on the agent machine, so any OpenSSL binary/library reported by your client's scan needs to be identified on that agent rather than assumed to be an Azure-hosted component. Microsoft recommends keeping self-hosted agents and task versions current. Also, Microsoft currently recommends moving from AzureFunctionApp@1 to AzureFunctionApp@2 for new deployments. @1 is maintained for legacy pipelines.

    On the affected agent, first identify exactly which OpenSSL installation the task is using:

    which openssl
    openssl version -a
    

    and inspect the task's working directory for bundled OpenSSL libraries/binaries. If the vulnerable OpenSSL is part of the task bundle, update the Azure Pipelines task/agent rather than replacing the system OpenSSL manually.

    If the scan is identifying the agent's system OpenSSL, update that package through the operating system's supported package manager. The Function App deployment task itself does not require you to pin a particular OpenSSL version.

    The key distinction is whether the scanner found OpenSSL under the agent OS or inside the Azure Pipelines task directory. That determines whether the remediation is an OS package update or a task/agent update.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.