models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
References
Configurations
History
21 Nov 2024, 06:01
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/pikepdf/pikepdf/blob/v2.10.0/docs/release_notes.rst#v2100 - Release Notes, Third Party Advisory | |
References | () https://github.com/pikepdf/pikepdf/commit/3f38f73218e5e782fe411ccbb3b44a793c0b343a - Patch, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36P4HTLBJPO524WMQWW57N3QRF4RFSJG/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QFLBBYGEDNXJ7FS6PIWTVI4T4BUPGEQ/ - |
03 Dec 2022, 14:25
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://github.com/pikepdf/pikepdf/blob/v2.10.0/docs/release_notes.rst#v2100 - Release Notes, Third Party Advisory |
23 Nov 2022, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
02 Jun 2021, 18:47
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* |
|
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3QFLBBYGEDNXJ7FS6PIWTVI4T4BUPGEQ/ - Mailing List, Third Party Advisory | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36P4HTLBJPO524WMQWW57N3QRF4RFSJG/ - Mailing List, Third Party Advisory |
Information
Published : 2021-04-01 20:15
Updated : 2024-11-21 06:01
NVD link : CVE-2021-29421
Mitre link : CVE-2021-29421
CVE.ORG link : CVE-2021-29421
JSON object : View
Products Affected
fedoraproject
- fedora
pikepdf_project
- pikepdf
CWE
CWE-611
Improper Restriction of XML External Entity Reference