Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Fixes #minor
Description
Component Governance: CVE-2021-33571, severity high
https://dev.azure.com/FuseLabs/SDK_v4/_componentGovernance/112465/alert/5974475?typeId=4354877
In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access control that is based on IP addresses.
Same fix also covers:
Component Governance: CVE-2021-31542, severity high
https://dev.azure.com/FuseLabs/SDK_v4/_componentGovernance/112465/alert/4935093?typeId=4354877
Component Governance: CVE-2021-33203, severity high
https://dev.azure.com/FuseLabs/SDK_v4/_componentGovernance/112465/alert/5199196?typeId=4354877
Specific Changes
Update django to v 2.2.24