Pillow < 9.0.0 security vulnerabilities

There are 3 security vulnerabilities in Pillow < 9.0.0. They are all considered critical.

  1. CVE-2022-22815
  2. CVE-2022-22816
  3. CVE-2022-22817

apps/microtvm/ethosu/requirements.txt lists Pillow==8.3.2.

3 Likes

Thanks! filed https://github.com/apache/tvm/issues/10238, i think this is not a formal requirement for TVM but just a loose end which was not updated.

1 Like