CVE-2023-50447 | Pillow up to 10.1.0 PIL.ImageMath.eval environment code injection (DLA 3724-1 / Nessus ID 210541)
A vulnerability was found in Pillow up to 10.1.0 and classified as problematic. This issue affects the function PIL.ImageMath.eval. The manipulation of the argument environment results in code injection.
This vulnerability is known as CVE-2023-50447. Access to the local network is required for this attack. No exploit is available.
It is suggested to upgrade the affected component.