Skip to content

Fix CG alerts 396991/396992: Resolve @azure/msal-browser 4.x vulnerability (MVS-2026-vmmw-f85q)#21986

Open
v-abhishera wants to merge 5 commits intomasterfrom
users/v-abhishera/CG396991fix
Open

Fix CG alerts 396991/396992: Resolve @azure/msal-browser 4.x vulnerability (MVS-2026-vmmw-f85q)#21986
v-abhishera wants to merge 5 commits intomasterfrom
users/v-abhishera/CG396991fix

Conversation

@v-abhishera
Copy link
Copy Markdown
Contributor

@v-abhishera v-abhishera commented Apr 9, 2026

Description:

Fixes AB#2365192,

Resolves CG alerts 396991 (@azure/msal-browser@4.28.1) and 396992 (@azure/msal-browser@4.28.2) — high-severity vulnerability related to auth code theft and COOP handling.

Root cause

azure-pipelines-tasks-azure-arm-rest@3.271.x depends on @azure/identity@4.13.0, which pulls @azure/msal-browser@4.x. The fix in arm-rest@3.272.1 updates to @azure/identity@4.13.1@azure/msal-browser@5.x.

Changes

Task Version Key dependency updates
AzureAppServiceManageV0 0.272.0 → 0.273.0 arm-rest ^3.272.1, utility-common ^3.272.0, task-lib ^5.2.8
AzureFunctionAppV1 1.272.0 → 1.273.0 arm-rest ^3.272.1, webdeployment-common ^4.272.1, task-lib ^5.2.8
AzureFunctionAppV2 2.272.0 → 2.273.0 arm-rest ^3.272.1, webdeployment-common ^4.272.1, task-lib ^5.2.8
AzureFunctionOnKubernetesV0 0.271.0 → 0.273.0 docker-common ^2.273.0, k8s-common ^2.272.0, task-lib ^5.2.8
AzureFunctionOnKubernetesV1 1.272.0 → 1.273.0 arm-rest ^3.272.1, docker-common ^2.273.0, k8s-common ^2.272.0, task-lib ^5.2.8
AzureResourceGroupDeploymentV2 2.272.0 → 2.273.0 arm-rest ^3.272.1, task-lib ^5.2.8
AzureResourceManagerTemplateDeploymentV3 3.272.0 → 3.273.0 arm-rest ^3.272.1, artifacts-common ^2.273.0, task-lib ^5.2.8
JenkinsDownloadArtifactsV1 1.272.0 → 1.273.0 arm-rest ^3.272.1, task-lib ^5.2.8
JenkinsDownloadArtifactsV2 2.272.0 → 2.273.0 arm-rest ^3.272.1, task-lib ^5.2.8

Testing

All tasks: L0 tests passing, npm audit fix applied

…nloadArtifactsV1 and V2

- Updated azure-pipelines-task-lib from ^5.2.6 to ^5.2.8
- Updated azure-pipelines-tasks-azure-arm-rest from ^3.271.1 to ^3.272.1
- Incremented task version from 1.272 to 1.273 for JenkinsDownloadArtifactsV1
- Incremented task version from 2.272 to 2.273 for JenkinsDownloadArtifactsV2
- Updated package-lock.json for JenkinsDownloadArtifactsV2 with new dependency versions
@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@v-abhishera
Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

1 similar comment
@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@v-abhishera v-abhishera changed the title Users/v abhishera/cg396991fix Fix CG alerts 396991/396992: Resolve @azure/msal-browser 4.x vulnerability (MVS-2026-vmmw-f85q) Apr 9, 2026
@v-abhishera v-abhishera marked this pull request as ready for review April 9, 2026 16:01
@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

@v-abhishera
Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

1 similar comment
@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines:
Successfully started running 3 pipeline(s).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant