QID 996819

Date Published: 2024-01-23

QID 996819: Python (Pip) Security Update for Pillow (GHSA-3f63-hfp8-52jq)

Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-3f63-hfp8-52jq for updates and patch information.
    Vendor References

    CVEs related to QID 996819

    Software Advisories
    Advisory ID Software Component Link
    GHSA-3f63-hfp8-52jq Pillow URL Logo github.com/advisories/GHSA-3f63-hfp8-52jq