models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
References
Configurations
History
21 Nov 2024, 06:01
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/pikepdf/pikepdf/blob/v2.10.0/docs/release_notes.rst#v2100 - Release Notes, Third Party Advisory | |
References | () https://github.com/pikepdf/pikepdf/commit/3f38f73218e5e782fe411ccbb3b44a793c0b343a - Patch, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36P4HTLBJPO524WMQWW57N3QRF4RFSJG/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QFLBBYGEDNXJ7FS6PIWTVI4T4BUPGEQ/ - |
Information
Published : 2021-04-01 20:15
Updated : 2024-11-21 06:01
NVD link : CVE-2021-29421
Mitre link : CVE-2021-29421
CVE.ORG link : CVE-2021-29421
JSON object : View
Products Affected
fedoraproject
- fedora
pikepdf_project
- pikepdf
CWE
CWE-611
Improper Restriction of XML External Entity Reference