From 6bb47852da60ebce9f82f0163c5506022d03d8be Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 30 May 2025 15:34:30 +0000 Subject: [PATCH] Publish GHSA-56pw-mpj4-fxww --- .../2023/10/GHSA-56pw-mpj4-fxww/GHSA-56pw-mpj4-fxww.json | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2023/10/GHSA-56pw-mpj4-fxww/GHSA-56pw-mpj4-fxww.json b/advisories/github-reviewed/2023/10/GHSA-56pw-mpj4-fxww/GHSA-56pw-mpj4-fxww.json index c76c55001aa..b69c907e2e3 100644 --- a/advisories/github-reviewed/2023/10/GHSA-56pw-mpj4-fxww/GHSA-56pw-mpj4-fxww.json +++ b/advisories/github-reviewed/2023/10/GHSA-56pw-mpj4-fxww/GHSA-56pw-mpj4-fxww.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-56pw-mpj4-fxww", - "modified": "2023-10-05T00:06:58Z", + "modified": "2025-05-30T15:32:54Z", "published": "2023-10-05T00:06:58Z", + "withdrawn": "2025-05-30T15:32:54Z", "aliases": [], - "summary": "Bundled libwebp in Pillow vulnerable", - "details": "Pillow versions before v10.0.1 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-5129 (previously CVE-2023-4863). Pillow v10.0.1 upgrades the bundled libwebp binary to v1.3.2.", + "summary": "Duplicate Advisory: Bundled libwebp in Pillow vulnerable", + "details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-56pw-mpj4-fxww. This link is maintained to preserve external references.\n\n## Original Description\nPillow versions before v10.0.1 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-5129 (previously CVE-2023-4863). Pillow v10.0.1 upgrades the bundled libwebp binary to v1.3.2.", "severity": [], "affected": [ {