Skip to content

Pillow critical vulnerability on latest LTS 15.4 #218

@mingue

Description

@mingue

Latest LTS image 15.4 uses python dependency Pillow on version 9.4.0 which contains the following critical vulnerability:

CVE-2023-50447
CVSS score: 8.1, CVSS exploitability score: 2.2
Fixed version: 10.2.0

is there any plan to fix this dependency?
alternatively are there any non LTS images that we can use in the meantime with more recent dependencies?

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions