High Arbitrary Code Execution
Package underscore
Patched in >=1.12.1
Dependency of tfx-cli [dev]
Path tfx-cli > azure-devops-node-api > typed-rest-client >
underscore
More info https://npmjs.com/advisories/1674
High Arbitrary Code Execution
Package underscore
Patched in >=1.12.1
Dependency of tfx-cli [dev]
More info https://npmjs.com/advisories/1674
found 2 high severity vulnerabilities in 230 scanned packages
2 vulnerabilities require manual review. See the full report for details.
According to microsoft/azure-devops-node-api#440 underscore was bumped up on 10.2.2.