Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-50447
HistoryJan 19, 2024 - 8:15 p.m.

Code injection

2024-01-1920:15:00
PRIOn knowledge base
www.prio-n.com
8
pillow imagemath codeexecution environmentparameter cve-2022-22817 securityvulnerability

9.4 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.6%

Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).

CPENameOperatorVersion
debian_linuxeq10.0
pillowle10.1.0