CVE-2023-50447 (High) detected in Pillow-8.2.0-cp37-cp37m-manylinux1_x86_64.whl, Pillow-8.1.1-cp37-cp37m-manylinux1_x86_64.whl #141
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2023-50447 - High Severity Vulnerability
Pillow-8.2.0-cp37-cp37m-manylinux1_x86_64.whl
Python Imaging Library (Fork)
Library home page: https://files.pythonhosted.org/packages/33/34/542152297dcc6c47a9dcb0685eac6d652d878ed3cea83bf2b23cb988e857/Pillow-8.2.0-cp37-cp37m-manylinux1_x86_64.whl
Path to dependency file: /tmp/ws-scm/easycv
Path to vulnerable library: /easycv
Dependency Hierarchy:
Pillow-8.1.1-cp37-cp37m-manylinux1_x86_64.whl
Python Imaging Library (Fork)
Library home page: https://files.pythonhosted.org/packages/b1/f9/5173fdbba404815d5109067ecde640dab908f4cd22b2c9de7bbedee46d67/Pillow-8.1.1-cp37-cp37m-manylinux1_x86_64.whl
Path to dependency file: /tmp/ws-scm/easycv
Path to vulnerable library: /easycv
Dependency Hierarchy:
Found in base branch: master
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
Publish Date: 2024-01-19
URL: CVE-2023-50447
Base Score Metrics:
Type: Upgrade version
Origin: https://www.openwall.com/lists/oss-security/2024/01/20/1
Release Date: 2024-01-19
Fix Resolution: pillow - 10.2.0
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: