models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
References
Configurations
History
21 Nov 2024, 06:01
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/pikepdf/pikepdf/blob/v2.10.0/docs/release_notes.rst#v2100 - Release Notes, Third Party Advisory | |
References | () https://github.com/pikepdf/pikepdf/commit/3f38f73218e5e782fe411ccbb3b44a793c0b343a - Patch, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36P4HTLBJPO524WMQWW57N3QRF4RFSJG/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QFLBBYGEDNXJ7FS6PIWTVI4T4BUPGEQ/ - |
07 Nov 2023, 03:32
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2021-04-01 20:15
Updated : 2024-11-21 06:01
NVD link : CVE-2021-29421
Mitre link : CVE-2021-29421
CVE.ORG link : CVE-2021-29421
JSON object : View
Products Affected
pikepdf_project
- pikepdf
fedoraproject
- fedora
CWE
CWE-611
Improper Restriction of XML External Entity Reference