ZeroHour

CVE-2021-23437

PoC
CVSS 3.1
7.5 high
EPSS
3%p87
Published
()
Modified
Description

The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.

Vendors
pythonfedoraproject
Products
pillow, fedora
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.