PT-2022-1455 · Pypi+9 · Pillow+9
Published
2022-01-02
·
Updated
2025-01-14
·
CVE-2022-22817
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Pillow versions prior to 9.0.1
Description
The issue allows evaluation of arbitrary expressions, such as ones that use the Python
exec method. A lambda expression could also be used, potentially enabling a remote attacker to execute arbitrary code in the system by passing a specially crafted file to the vulnerable library.Recommendations
For Pillow versions prior to 9.0.0, update to version 9.0.1 to resolve the issue.
For Pillow version 9.0.0, update to version 9.0.1 to fully restrict builtins available to lambda expressions and prevent exploitation.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Pillow
Red Hat
Red Os
Rocky Linux
Ubuntu