Security issue found in Pillow prior to 6.2.0 #2955

Closed
opened 2025-12-29 18:23:59 +01:00 by adam · 2 comments
Owner

Originally created by @dgarros on GitHub (Oct 14, 2019).

Originally assigned to: @dgarros on GitHub.

Netbox Version: 2.6.6

Proposed Changes

Update Pillow version in the requirements.txt file from 6.0.0 to 6.2.0

Justification

A new CVE just got reporter regarding Pillow, it's affecting all version prior to 6.2.0 and currently netbox requires 6.0.0
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16865

the change was initially proposed in #3597 but it got closed

Originally created by @dgarros on GitHub (Oct 14, 2019). Originally assigned to: @dgarros on GitHub. Netbox Version: 2.6.6 ### Proposed Changes Update Pillow version in the requirements.txt file from 6.0.0 to 6.2.0 ### Justification A new CVE just got reporter regarding Pillow, it's affecting all version prior to 6.2.0 and currently netbox requires 6.0.0 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16865 > the change was initially proposed in #3597 but it got closed
adam closed this issue 2025-12-29 18:23:59 +01:00
Author
Owner

@jeremystretch commented on GitHub (Oct 15, 2019):

@dgarros Please note the current version of NetBox affected in the issue.

@jeremystretch commented on GitHub (Oct 15, 2019): @dgarros Please note the current version of NetBox affected in the issue.
Author
Owner

@dgarros commented on GitHub (Oct 15, 2019):

@jeremystretch Done, I've updated my initial message

@dgarros commented on GitHub (Oct 15, 2019): @jeremystretch Done, I've updated my initial message
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/netbox#2955