-
Notifications
You must be signed in to change notification settings - Fork 43
Open
Labels
Security: highRemediate within 30 daysRemediate within 30 days
Milestone
Description
Overview
Affected versions of this package are vulnerable to Out-of-bounds Write in the _setimage() functions in encode.c and decode.c, which are exploitable via Image.open(). An attacker can execute arbitrary code by supplying a malicious PSD image file.
https://app.snyk.io/vuln/SNYK-PYTHON-PILLOW-15265439
Security information
Factors contributing to the scoring:
Snyk: CVSS v4.0 8.5 - High Severity | CVSS v3.1 7.8 - High Severity
NVD: Not available. NVD has not yet published its analysis.
Why are the scores different? Learn how Snyk evaluates vulnerability scores
Action item:
- upgrade pillow to version 12.1.1 or higher
Completion criteria:
- The pillow package has been updated, and the Snyk vulnerability has been remediated.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Security: highRemediate within 30 daysRemediate within 30 days
Type
Projects
Status
🗄️ PI backlog