Commit f320ca9
authored
security: bump pillow to 10.2 to fix CVE-2022-22817 (#165)
Not a real problem since it's just a test dependency. Still here comes
the fix for
https://github.com/advisories/GHSA-3f63-hfp8-52jq/dependabot?query=user%3Ageotribu
> Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code
Execution via the environment parameter, a different vulnerability than
CVE-2022-22817 (which was about the expression parameter).1 file changed
+1
-1
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
4 | | - | |
| 4 | + | |
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
0 commit comments