Skip to content

Fix CG alert 433156: update @xmldom/xmldom to 0.8.13 via webdeployment-common in 8 tasks#22086

Open
v-abhishera wants to merge 4 commits intomasterfrom
users/v-abhishera/fix-cg-433156-xmldom
Open

Fix CG alert 433156: update @xmldom/xmldom to 0.8.13 via webdeployment-common in 8 tasks#22086
v-abhishera wants to merge 4 commits intomasterfrom
users/v-abhishera/fix-cg-433156-xmldom

Conversation

@v-abhishera
Copy link
Copy Markdown
Contributor

@v-abhishera v-abhishera commented Apr 27, 2026

AB#2381967
Summary:
Resolves CG alert 433156 (CVE-2026-41674 — xmldom XML injection through unvalidated DocumentType serialization, severity: high) by updating azure-pipelines-tasks-webdeployment-common from ^4.272.1 to ^4.274.0. The updated common package resolves @xmldom/xmldom to 0.8.13 from npm registry instead of 0.8.12 via git reference.

Affected tasks:

Task Version Deprecated
AzureFunctionAppContainerV1 1.274.0 No
AzureFunctionAppV1 1.274.0 No
AzureFunctionAppV2 2.274.0 No
AzureMysqlDeploymentV1 1.274.0 Yes (security fix)
AzureRmWebAppDeploymentV3 3.274.0 Yes (security fix)
AzureRmWebAppDeploymentV4 4.274.0 Yes (security fix)
AzureRmWebAppDeploymentV5 5.274.0 Yes (security fix)
AzureWebAppContainerV1 1.274.0 No

Testing: All 8 tasks build successfully and pass L0 tests.

…ppDeploymentV5

- Updated package.json and task.json files to reflect the new version.
- Updated dependencies in package-lock.json for AzureRmWebAppDeploymentV4 and AzureRmWebAppDeploymentV5.
- Updated localization files for AzureRmWebAppDeploymentV4 and AzureRmWebAppDeploymentV5.
- Updated package-lock.json and package.json for AzureWebAppContainerV1 to use new version 4.274.0 of azure-pipelines-tasks-webdeployment-common.
- Updated dependencies in package-lock.json for AzureWebAppContainerV1.
@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@v-abhishera v-abhishera marked this pull request as ready for review April 27, 2026 13:28
@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@v-abhishera
Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@v-abhishera
Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant