CVE-2022-22817

Related Vulnerabilities: CVE-2022-22817  

PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method.

Description

The MITRE CVE dictionary describes this issue as:

PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method.

Additional Information

  • Bugzilla 2042527: CVE-2022-22817 python-pillow: PIL.ImageMath.eval allows evaluation of arbitrary expressions
  • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
  • FAQ: Frequently asked questions about CVE-2022-22817