Open mend-for-github-com[bot] opened 7 months ago
:heavy_check_mark: This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.
:information_source: This issue was automatically re-opened by Mend because the vulnerable library in the specific branch(es) has been detected in the Mend inventory.
Vulnerable Library - pillow-10.2.0-cp38-cp38-manylinux_2_28_x86_64.whl
Python Imaging Library (Fork)
Library home page: https://files.pythonhosted.org/packages/41/a3/8644f5e4680e9e4b51b306a4042699bed29ae035181d412971218e95fd40/pillow-10.2.0-cp38-cp38-manylinux_2_28_x86_64.whl
Path to dependency file: /requirements.txt
Path to vulnerable library: /requirements.txt
Found in HEAD commit: 980c33eab0567755c6395fde59d9ac00f8cd245a
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2024-28219
### Vulnerable Library - pillow-10.2.0-cp38-cp38-manylinux_2_28_x86_64.whlPython Imaging Library (Fork)
Library home page: https://files.pythonhosted.org/packages/41/a3/8644f5e4680e9e4b51b306a4042699bed29ae035181d412971218e95fd40/pillow-10.2.0-cp38-cp38-manylinux_2_28_x86_64.whl
Path to dependency file: /requirements.txt
Path to vulnerable library: /requirements.txt
Dependency Hierarchy: - :x: **pillow-10.2.0-cp38-cp38-manylinux_2_28_x86_64.whl** (Vulnerable Library)
Found in HEAD commit: 980c33eab0567755c6395fde59d9ac00f8cd245a
Found in base branch: main
### Vulnerability DetailsIn _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.
Publish Date: 2024-04-03
URL: CVE-2024-28219
### CVSS 3 Score Details (6.7)Base Score Metrics: - Exploitability Metrics: - Attack Vector: Local - Attack Complexity: High - Privileges Required: Low - User Interaction: Required - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High
For more information on CVSS3 Scores, click here. ### Suggested FixType: Upgrade version
Origin: https://pillow.readthedocs.io/en/stable/releasenotes/10.3.0.html#security
Release Date: 2024-04-03
Fix Resolution: 10.3.0
:rescue_worker_helmet: Automatic Remediation will be attempted for this issue.:rescue_worker_helmet:Automatic Remediation will be attempted for this issue.