Lack of data validation - Path Traversal In pillow
Description
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.