Skip to content

Conversation

@vseanreesermsft
Copy link
Contributor

No description provided.

dotnet-bot and others added 14 commits November 2, 2021 20:36
…Path should be surrounded by quotes in case path contains spaces to avoid possible escalation of privilege

MSRC: 68089 - EoP - aspNetCore processPath should be surrounded by quotes in case path contains spaces to avoid possible escalation of privileges CRM:0331001776

Fixes an issue with a path not being properly escaped so spaces can result in executing an app in the parent directory. The fix just adds double quotes around the argument.

Regression:
No

Risk:
Low

Verification
Manual

Packaging changes reviewed?
TBD - this change is in the ANCM dll
…ng/internal/dotnet-efcore

This pull request updates the following dependencies

[marker]: <> (Begin:Coherency Updates)
## Coherency Updates

The following updates ensure that dependencies with a *CoherentParentDependency*
attribute were produced in a build used as input to the parent dependency's build.
See [Dependency Description Format](https://github.com/dotnet/arcade/blob/master/Documentation/DependencyDescriptionFormat.md#dependency-description-overview)

[DependencyUpdate]: <> (Begin)

- **Coherency Updates**:
  - **Microsoft.Extensions.Logging**: from 3.1.21 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.AspNetCore.Analyzer.Testing**: from 3.1.21-servicing.21522.3 to 3.1.22-servicing.21552.1 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.AspNetCore.BenchmarkRunner.Sources**: from 3.1.21-servicing.21522.3 to 3.1.22-servicing.21552.1 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.ActivatorUtilities.Sources**: from 3.1.21-servicing.21522.3 to 3.1.22-servicing.21552.1 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Caching.Abstractions**: from 3.1.21 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Caching.Memory**: from 3.1.21 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Caching.SqlServer**: from 3.1.21 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Caching.StackExchangeRedis**: from 3.1.21 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.CommandLineUtils.Sources**: from 3.1.21-servicing.21522.3 to 3.1.22-servicing.21552.1 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.Abstractions**: from 3.1.21 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.AzureKeyVault**: from 3.1.21 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.Binder**: from 3.1.21 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.CommandLine**: from 3.1.21 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.EnvironmentVariables**: from 3.1.21 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.FileExtensions**: from 3.1.21 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.Ini**: from 3.1.21 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.Json**: from 3.1.21 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.KeyPerFile**: from 3.1.21 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.UserSecrets**: from 3.1.21 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.Xml**: from 3.1.21 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configu...
…ng/internal/dotnet-efcore

This pull request updates the following dependencies

[marker]: <> (Begin:e908e90a-0c22-4c54-b254-08d79557a113)
## From https://dev.azure.com/dnceng/internal/_git/dotnet-efcore
- **Subscription**: e908e90a-0c22-4c54-b254-08d79557a113
- **Build**: 20211117.1
- **Date Produced**: November 17, 2021 10:19:23 AM UTC
- **Commit**: 2056a301a2ce2c9b5c86ef028455cb1f0c10f3cc
- **Branch**: refs/heads/internal/release/3.1

[DependencyUpdate]: <> (Begin)

- **Updates**:
  - **Microsoft.EntityFrameworkCore.Tools**: [from 3.1.21 to 3.1.22][1]
  - **Microsoft.EntityFrameworkCore.SqlServer**: [from 3.1.21 to 3.1.22][1]
  - **dotnet-ef**: [from 3.1.21 to 3.1.22][1]
  - **Microsoft.EntityFrameworkCore**: [from 3.1.21 to 3.1.22][1]
  - **Microsoft.EntityFrameworkCore.InMemory**: [from 3.1.21 to 3.1.22][1]
  - **Microsoft.EntityFrameworkCore.Relational**: [from 3.1.21 to 3.1.22][1]
  - **Microsoft.EntityFrameworkCore.Sqlite**: [from 3.1.21 to 3.1.22][1]
  - **Microsoft.Extensions.Logging**: [from 3.1.22 to 3.1.22][2]
  - **Microsoft.NETCore.App.Runtime.win-x64**: [from 3.1.22 to 3.1.22][3]
  - **Microsoft.AspNetCore.Analyzer.Testing**: [from 3.1.22-servicing.21554.4 to 3.1.22-servicing.21566.3][2]
  - **Microsoft.AspNetCore.BenchmarkRunner.Sources**: [from 3.1.22-servicing.21554.4 to 3.1.22-servicing.21566.3][2]
  - **Microsoft.Extensions.ActivatorUtilities.Sources**: [from 3.1.22-servicing.21554.4 to 3.1.22-servicing.21566.3][2]
  - **Microsoft.Extensions.Caching.Abstractions**: [from 3.1.22 to 3.1.22][2]
  - **Microsoft.Extensions.Caching.Memory**: [from 3.1.22 to 3.1.22][2]
  - **Microsoft.Extensions.Caching.SqlServer**: [from 3.1.22 to 3.1.22][2]
  - **Microsoft.Extensions.Caching.StackExchangeRedis**: [from 3.1.22 to 3.1.22][2]
  - **Microsoft.Extensions.CommandLineUtils.Sources**: [from 3.1.22-servicing.21554.4 to 3.1.22-servicing.21566.3][2]
  - **Microsoft.Extensions.Configuration.Abstractions**: [from 3.1.22 to 3.1.22][2]
  - **Microsoft.Extensions.Configuration.AzureKeyVault**: [from 3.1.22 to 3.1.22][2]
  - **Microsoft.Extensions.Configuration.Binder**: [from 3.1.22 to 3.1.22][2]
  - **Microsoft.Extensions.Configuration.CommandLine**: [from 3.1.22 to 3.1.22][2]
  - **Microsoft.Extensions.Configuration.EnvironmentVariables**: [from 3.1.22 to 3.1.22][2]
  - **Microsoft.Extensions.Configuration.FileExtensions**: [from 3.1.22 to 3.1.22][2]
  - **Microsoft.Extensions.Configuration.Ini**: [from 3.1.22 to 3.1.22][2]
  - **Microsoft.Extensions.Configuration.Json**: [from 3.1.22 to 3.1.22][2]
  - **Microsoft.Extensions.Configuration.KeyPerFile**: [from 3.1.22 to 3.1.22][2]
  - **Microsoft.Extensions.Configuration.UserSecrets**: [from 3.1.22 to 3.1.22][2]
  - **Microsoft.Extensions.Configuration.Xml**: [from 3.1.22 to 3.1.22][2]
  - **Microsoft.Extensions.Configuration**: [from 3.1.22 to 3.1.22][2]
  - **Microsoft.Extensions.DependencyInjection.Abstractions**: [from 3.1.22 to 3.1.22][2]
  - **Microsoft.Extensions.Dependency...
…ng/internal/dotnet-efcore

This pull request updates the following dependencies

[marker]: <> (Begin:Coherency Updates)
## Coherency Updates

The following updates ensure that dependencies with a *CoherentParentDependency*
attribute were produced in a build used as input to the parent dependency's build.
See [Dependency Description Format](https://github.com/dotnet/arcade/blob/master/Documentation/DependencyDescriptionFormat.md#dependency-description-overview)

[DependencyUpdate]: <> (Begin)

- **Coherency Updates**:
  - **Microsoft.Extensions.Logging**: from 3.1.22 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.NETCore.App.Runtime.win-x64**: from 3.1.22 to 3.1.22 (parent: Microsoft.Extensions.Logging)
  - **Microsoft.AspNetCore.Analyzer.Testing**: from 3.1.22-servicing.21566.3 to 3.1.22-servicing.21571.3 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.AspNetCore.BenchmarkRunner.Sources**: from 3.1.22-servicing.21566.3 to 3.1.22-servicing.21571.3 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.ActivatorUtilities.Sources**: from 3.1.22-servicing.21566.3 to 3.1.22-servicing.21571.3 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Caching.Abstractions**: from 3.1.22 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Caching.Memory**: from 3.1.22 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Caching.SqlServer**: from 3.1.22 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Caching.StackExchangeRedis**: from 3.1.22 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.CommandLineUtils.Sources**: from 3.1.22-servicing.21566.3 to 3.1.22-servicing.21571.3 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.Abstractions**: from 3.1.22 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.AzureKeyVault**: from 3.1.22 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.Binder**: from 3.1.22 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.CommandLine**: from 3.1.22 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.EnvironmentVariables**: from 3.1.22 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.FileExtensions**: from 3.1.22 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.Ini**: from 3.1.22 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.Json**: from 3.1.22 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.KeyPerFile**: from 3.1.22 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configuration.UserSecrets**: from 3.1.22 to 3.1.22 (parent: Microsoft.EntityFrameworkCore)
  - **Microsoft.Extensions.Configura...
…ng/internal/dotnet-razor-tooling

This pull request updates the following dependencies

[marker]: <> (Begin:7bf32a0c-3505-43af-42b0-08d79559e63d)
## From https://dev.azure.com/dnceng/internal/_git/dotnet-razor-tooling
- **Subscription**: 7bf32a0c-3505-43af-42b0-08d79559e63d
- **Build**: 20211121.3
- **Date Produced**: November 22, 2021 4:44:41 AM UTC
- **Commit**: 65c8532d63fd06b3eb7cbdf52ac0bc77df58e528
- **Branch**: refs/heads/internal/release/3.1

[DependencyUpdate]: <> (Begin)

- **Updates**:
  - **Microsoft.AspNetCore.Razor.Language**: [from 3.1.21 to 3.1.22][1]
  - **Microsoft.CodeAnalysis.Razor**: [from 3.1.21 to 3.1.22][1]
  - **Microsoft.NET.Sdk.Razor**: [from 3.1.21 to 3.1.22][1]
  - **Microsoft.AspNetCore.Mvc.Razor.Extensions**: [from 3.1.21 to 3.1.22][1]

[1]: https://dev.azure.com/dnceng/internal/_git/dotnet-razor-tooling/branches?baseVersion=GC7803678&targetVersion=GC65c8532&_a=files

[DependencyUpdate]: <> (End)

[marker]: <> (End:7bf32a0c-3505-43af-42b0-08d79559e63d)
@ghost ghost added this to the 3.1.x milestone Dec 14, 2021
@ghost
Copy link

ghost commented Dec 14, 2021

Hi @vseanreesermsft. If this is not a tell-mode PR, please make sure to follow the instructions laid out in the servicing process document.
Otherwise, please add tell-mode label.

@dougbu dougbu added area-infrastructure Includes: MSBuild projects/targets, build scripts, CI, Installers and shared framework tell-mode Indicates a PR which is being merged during tell-mode labels Dec 15, 2021
@vseanreesermsft vseanreesermsft requested a review from a team as a code owner December 15, 2021 01:39
- reenable baseline validation

nit: Remove (empty) dotnet-aspnetcore-tooling feed mentions
@dougbu dougbu enabled auto-merge December 15, 2021 03:44
@dougbu dougbu merged commit 64e134e into dotnet:release/3.1 Dec 15, 2021
@dougbu dougbu modified the milestones: 3.1.x, 3.1.23 Dec 15, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-infrastructure Includes: MSBuild projects/targets, build scripts, CI, Installers and shared framework tell-mode Indicates a PR which is being merged during tell-mode

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants