QID 980786

QID 980786: Python (pip) Security Update for pillow (GHSA-98vv-pw6r-q6q4)

The package pillow from 0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-98vv-pw6r-q6q4 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980786

    Software Advisories
    Advisory ID Software Component Link
    GHSA-98vv-pw6r-q6q4 pillow URL Logo github.com/advisories/GHSA-98vv-pw6r-q6q4