From df09113c135cfba5cae2e10b788a2f364920a0e0 Mon Sep 17 00:00:00 2001 From: sbalia Date: Mon, 2 May 2022 19:10:07 +0200 Subject: [PATCH] This affects the package set-value before 2.0.1, and starting with 3.0.0 but prior to 4.0.1. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays. --- Tasks/AppCenterTestV1/package-lock.json | 8 ++++---- Tasks/AppCenterTestV1/task.json | 2 +- Tasks/AppCenterTestV1/task.loc.json | 2 +- 3 files changed, 6 insertions(+), 6 deletions(-) diff --git a/Tasks/AppCenterTestV1/package-lock.json b/Tasks/AppCenterTestV1/package-lock.json index 25d602295f1f..7ac75d121568 100644 --- a/Tasks/AppCenterTestV1/package-lock.json +++ b/Tasks/AppCenterTestV1/package-lock.json @@ -1,7 +1,7 @@ { "name": "vsts-tasks-appcentertest", "version": "1.0.0", - "lockfileVersion": 1, + "lockfileVersion": 2, "requires": true, "dependencies": { "ajv": { @@ -2679,9 +2679,9 @@ "integrity": "sha1-SysbJ+uAip+NzEgaWOXlb1mfP2E=" }, "set-value": { - "version": "2.0.0", - "resolved": "https://registry.npmjs.org/set-value/-/set-value-2.0.0.tgz", - "integrity": "sha512-hw0yxk9GT/Hr5yJEYnHNKYXkIA8mVJgd9ditYZCe16ZczcaELYYcfvaXesNACk2O8O0nTiPQcQhGUQj8JLzeeg==", + "version": "2.0.1", + "resolved": "https://registry.npmjs.org/set-value/-/set-value-2.0.1.tgz", + "integrity": "sha512-JxHc1weCN68wRY0fhCoXpyK55m/XPHafOmK4UWD7m2CI14GMcFypt4w/0+NV5f/ZMby2F6S2wwA7fgynh9gWSw==", "requires": { "extend-shallow": "^2.0.1", "is-extendable": "^0.1.1", diff --git a/Tasks/AppCenterTestV1/task.json b/Tasks/AppCenterTestV1/task.json index add204d1fcdd..654e875cc45d 100644 --- a/Tasks/AppCenterTestV1/task.json +++ b/Tasks/AppCenterTestV1/task.json @@ -12,7 +12,7 @@ "author": "Microsoft Corporation", "version": { "Major": 1, - "Minor": 198, + "Minor": 204, "Patch": 0 }, "groups": [ diff --git a/Tasks/AppCenterTestV1/task.loc.json b/Tasks/AppCenterTestV1/task.loc.json index f6a4f93e302b..85087c0c728e 100644 --- a/Tasks/AppCenterTestV1/task.loc.json +++ b/Tasks/AppCenterTestV1/task.loc.json @@ -12,7 +12,7 @@ "author": "Microsoft Corporation", "version": { "Major": 1, - "Minor": 198, + "Minor": 204, "Patch": 0 }, "groups": [