CVE-2023-50447 is a high-severity arbitrary code execution vulnerability affecting Pillow versions up to 10.1.0, specifically through the PIL.ImageMath.eval function's environment parameter. This network-exploitable flaw, with high attack complexity, could lead to complete compromise of confidentiality, integrity, and availability. While rated with a CVSS score of 8.1, there is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.1.0CPE matchmatch criteria | cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.0 SP 9 Security Updates
Jun 17, 2024HP ThinPro 8.0 SP 9 Security Updates
Jun 17, 2024HP ThinPro 8.1 SP 2 Security Updates
Apr 12, 2024HP ThinPro 8.1 SP 2 Security Updates
Apr 12, 2024Arbitrary Code Execution in Pillow
Jan 19, 2024pillow: Arbitrary Code Execution via the environment parameter
Jan 19, 2024Pillow vulnerabilities