Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Upgraded versions for dependent repo and included gunicorn as http se… (
#35) * Upgraded versions for dependent repo and included gunicorn as http server - reverted redis version as dependency also needed to be chaged. - Versions for flask updated to available - Versions for gitpython updated to >=3.1.20 - Versions for marshmellow updated to >=3.14.1 - Versions for requests updated to >=2.27.1 - contextvars library added * - resolved another critical vulerability CVE-2022-24439 Detail All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments. Resolution :: Upgrade GitPython to version 3.1.30 or higher. https://nvd.nist.gov/vuln/detail/CVE-2022-24439 https://security.snyk.io/vuln/SNYK-PYTHON-GITPYTHON-3113858
- Loading branch information