Fix Dependabot security vulnerabilities in monitoring_flask_backend
Summary
Address 4 Dependabot security alerts in monitoring_flask_backend/requirements.txt:
High Severity
- CVE-2024-1135: Request smuggling leading to endpoint restriction bypass in Gunicorn
- CVE-2024-1135: Gunicorn HTTP Request/Response Smuggling vulnerability
Moderate Severity
-
CVE-2024-35195: Requests
Sessionobject does not verify requests after making first request with verify=False - .netrc credentials leak: Requests vulnerable to .netrc credentials leak via malicious URLs
Resolution
Update dependencies:
-
gunicorn: 21.2.0 → 23.0.0 -
requests: 2.31.0 → 2.32.3
SOC2 Compliance
This issue tracks security vulnerability remediation for compliance purposes.