containers icon indicating copy to clipboard operation
containers copied to clipboard

Pillow critical vulnerability on latest LTS 15.4

Open mingue opened this issue 6 months ago • 0 comments

Latest LTS image 15.4 uses python dependency Pillow on version 9.4.0 which contains the following critical vulnerability:

CVE-2023-50447 CVSS score: 8.1, CVSS exploitability score: 2.2 Fixed version: 10.2.0

is there any plan to fix this dependency? alternatively are there any non LTS images that we can use in the meantime with more recent dependencies?

Thanks!

mingue avatar Apr 23 '25 11:04 mingue