cbcvebase.
CVE-2022-24303
published 2022-03-28

CVE-2022-24303: Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.

PriorityP348critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
2.81%
84.8th percentile
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianpillow< pillow 9.0.1-1 (bookworm)pillow 9.0.1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
paloaltopan-os
pythonpillow< 9.0.19.0.1
pythonpillow>= 0 < 8.1.2+dfsg-0.3+deb11u38.1.2+dfsg-0.3+deb11u3
pythonpillow>= 0 < 9.0.1-19.0.1-1
pythonpillow>= 0 < 9.0.1-19.0.1-1
pythonpillow>= 0 < 9.0.1-19.0.1-1
pythonpillow>= 0 < 9.0.19.0.1
pythonpillow>= 0 < 7.0.0-4ubuntu0.77.0.0-4ubuntu0.7
pythonpillow>= 0 < 9.0.1-1ubuntu0.19.0.1-1ubuntu0.1

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
vendor_ubuntu9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.