cbcvebase.
CVE-2022-24303
published 2022-03-28

CVE-2022-24303: Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.

critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianpillow< pillow 9.0.1-1 (bookworm)pillow 9.0.1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
paloaltopan-os
pythonpillow< 9.0.19.0.1
pythonpillow>= 0 < 8.1.2+dfsg-0.3+deb11u38.1.2+dfsg-0.3+deb11u3
pythonpillow>= 0 < 9.0.1-19.0.1-1
pythonpillow>= 0 < 9.0.1-19.0.1-1
pythonpillow>= 0 < 9.0.1-19.0.1-1
pythonpillow>= 0 < 9.0.19.0.1
pythonpillow>= 0 < 7.0.0-4ubuntu0.77.0.0-4ubuntu0.7
pythonpillow>= 0 < 9.0.1-1ubuntu0.19.0.1-1ubuntu0.1

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
osv9.1CRITICAL