First published: Fri Sep 03 2021(Updated: )
The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
Credit: report@snyk.io report@snyk.io report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Python Pillow | >=5.2.0<8.3.2 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
pip/pillow | >=5.2.0<8.3.2 | 8.3.2 |
fedoraproject fedora | =33 | |
fedoraproject fedora | =34 | |
Fedora | =33 | |
Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Vulnerability CVE-2021-23437 is a Regular Expression Denial of Service (ReDoS) vulnerability in the package pillow version 5.2.0 and before 8.3.2.
The vulnerability CVE-2021-23437 allows an attacker to perform a Regular Expression Denial of Service (ReDoS) attack via the getrgb function in the pillow package.
The severity level of vulnerability CVE-2021-23437 is high, with a severity value of 7.5.
To fix vulnerability CVE-2021-23437, update the pillow package to version 8.3.2 or above.
You can find more information about vulnerability CVE-2021-23437 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-23437), [GitHub](https://github.com/python-pillow/Pillow/commit/9e08eb8f78fdfd2f476e1b20b7cf38683754866b), [Pillow Release Notes](https://pillow.readthedocs.io/en/stable/releasenotes/8.3.2.html).