GHSA-98vv-pw6r-q6q4

Suggest an improvement
Source
https://github.com/advisories/GHSA-98vv-pw6r-q6q4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-98vv-pw6r-q6q4/GHSA-98vv-pw6r-q6q4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-98vv-pw6r-q6q4
Aliases
Published
2021-09-07T23:08:10Z
Modified
2024-10-09T21:08:55.452380Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Uncontrolled Resource Consumption in pillow
Details

The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.

References

Affected packages

PyPI / pillow

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.2.0
Fixed
8.3.2

Affected versions

5.*

5.2.0
5.3.0
5.4.0.dev0
5.4.0
5.4.1

6.*

6.0.0
6.1.0
6.2.0
6.2.1
6.2.2

7.*

7.0.0
7.1.0
7.1.1
7.1.2
7.2.0

8.*

8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.2.0
8.3.0
8.3.1