CVE-2023-50447

Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
Configurations

Configuration 1 (hide)

cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-01-19 20:15

Updated : 2024-03-27 21:15


NVD link : CVE-2023-50447

Mitre link : CVE-2023-50447

CVE.ORG link : CVE-2023-50447


JSON object : View

Products Affected

python

  • pillow

debian

  • debian_linux
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')