CVE-2021-23437: Regular Expression Denial of Service (ReDoS)
The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is vulnerability CVE-2021-23437?
Vulnerability CVE-2021-23437 is a Regular Expression Denial of Service (ReDoS) vulnerability in the package pillow version 5.2.0 and before 8.3.2.
How does the vulnerability CVE-2021-23437 impact the affected software?
The vulnerability CVE-2021-23437 allows an attacker to perform a Regular Expression Denial of Service (ReDoS) attack via the getrgb function in the pillow package.
What is the severity level of vulnerability CVE-2021-23437?
The severity level of vulnerability CVE-2021-23437 is high, with a severity value of 7.5.
How can I fix vulnerability CVE-2021-23437?
To fix vulnerability CVE-2021-23437, update the pillow package to version 8.3.2 or above.
Where can I find more information about vulnerability CVE-2021-23437?
You can find more information about vulnerability CVE-2021-23437 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-23437), [GitHub](https://github.com/python-pillow/Pillow/commit/9e08eb8f78fdfd2f476e1b20b7cf38683754866b), [Pillow Release Notes](https://pillow.readthedocs.io/en/stable/releasenotes/8.3.2.html).