You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This package does not cause a significant external security vulnerability since only approved and authenticated Wagtail users can upload resources to our system. We plan to patch this package when we upgrade our Wagtail version to the latest 2.11 LTS.
patphongs
changed the title
[Snyk: High] Pillow Out-of-bounds Read (4/2/21)
[Snyk: High] Pillow Out-of-bounds Read (6/2/21)
Mar 4, 2021
patphongs
changed the title
[Snyk: High] Pillow Out-of-bounds Read (6/2/21)
[Snyk: Low] Pillow Out-of-bounds Read (6/2/21)
Mar 4, 2021
@hcaofec commented on Wed Mar 03 2021
Introduced through: pillow@7.1.0 and wagtail@2.7.4
Exploit maturity: NO KNOWN EXPLOIT
Detailed paths
Introduced through: project@0.0.0 › pillow@7.1.0
Remediation: No remediation path available.
Introduced through: project@0.0.0 › wagtail@2.7.4 › Pillow@7.1.0
Remediation: No remediation path available.
Overview
Pillow is a PIL (Python Imaging Library) fork.
Affected versions of this package are vulnerable to Out-of-bounds Read due to invalid tile boundaries lead.
More info:
https://app.snyk.io/vuln/SNYK-PYTHON-PILLOW-1080635
The text was updated successfully, but these errors were encountered: