CVE-2023-50447: Pillow 10.2.0 released, fixes CVE-2023-50447
Pillow could allow a remote attacker to execute arbitrary code on the system, caused by improper neutralization of user supplied-input by the PIL.ImageMath.eval function. By sending a specially crafted request using keys that leverage the environment parameter, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Other sources
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
— Ubuntu
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50447?
CVE-2023-50447 is considered a critical vulnerability that allows arbitrary code execution on affected systems.
How do I fix CVE-2023-50447?
To fix CVE-2023-50447, update Pillow to version 10.2.0 or later, or apply the appropriate patch for affected software such as IBM Cognos Analytics.
Which versions of Pillow are affected by CVE-2023-50447?
CVE-2023-50447 affects multiple versions of Pillow, specifically those prior to 10.2.0.
Is my version of Pillow vulnerable to CVE-2023-50447?
You are vulnerable to CVE-2023-50447 if you are using Pillow versions below 10.2.0.
What types of software are impacted by CVE-2023-50447?
CVE-2023-50447 impacts Pillow installations across various environments, including Ubuntu, Debian, and products like IBM Cognos Analytics.