cbcvebase.
CVE-2021-23437
published 2021-09-03

CVE-2021-23437: The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.

PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.15%
86.5th percentile
The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianpillow< pillow 8.3.2-1 (bookworm)pillow 8.3.2-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
pythonpillow< unspecifiedunspecified
pythonpillow>= 0 < 8.1.2+dfsg-0.3+deb11u38.1.2+dfsg-0.3+deb11u3
pythonpillow>= 0 < 8.3.2-18.3.2-1
pythonpillow>= 0 < 8.3.2-18.3.2-1
pythonpillow>= 0 < 8.3.2-18.3.2-1
pythonpillow>= 0 < 9e08eb8f78fdfd2f476e1b20b7cf38683754866b9e08eb8f78fdfd2f476e1b20b7cf38683754866b
pythonpillow>= 0 < 8.3.28.3.2
pythonpillow>= 0 < 5.1.0-1ubuntu0.85.1.0-1ubuntu0.8
pythonpillow>= 0 < 5.1.0-1ubuntu0.75.1.0-1ubuntu0.7
pythonpillow>= 0 < 7.0.0-4ubuntu0.67.0.0-4ubuntu0.6
pythonpillow>= 0 < 7.0.0-4ubuntu0.57.0.0-4ubuntu0.5
pythonpillow>= 0 < 2.3.0-1ubuntu3.4+esm32.3.0-1ubuntu3.4+esm3
pythonpillow>= 0 < 3.1.2-0ubuntu1.6+esm13.1.2-0ubuntu1.6+esm1
pythonpillow>= 5.2.0 < 8.3.28.3.2
pythonpillow>= 5.2.0 < 8.3.28.3.2
pythonpillow>= unspecified < 8.3.28.3.2

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.