Lucene search

K
f5F5F5:K000138866
HistoryMar 09, 2024 - 12:00 a.m.

K000138866 : Python Pillow vulnerability CVE-2023-50447

2024-03-0900:00:00
my.f5.com
22
pillow
arbitrary code execution
cve-2023-50447
security advisory

AI Score

7.1

Confidence

Low

EPSS

0.004

Percentile

73.5%

Security Advisory Description

Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter). (CVE-2023-50447)

Impact

There is no impact; F5 products are not affected by this vulnerability.