Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33586
HistoryJan 11, 2022 - 8:52 a.m.

Information Dislcosure

2022-01-1108:52:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.003 Low

EPSS

Percentile

68.5%

pillow is vulnerable to information disclosure. The vulnerability exists because the pillow doesn’t restrict the builtins available in eval function of ImageMath.py which allows an attacker to evaluate arbitrary expressions and gain access to sensitive information.