models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
References
Link | Resource |
---|---|
https://github.com/pikepdf/pikepdf/commit/3f38f73218e5e782fe411ccbb3b44a793c0b343a | Patch Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3QFLBBYGEDNXJ7FS6PIWTVI4T4BUPGEQ/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36P4HTLBJPO524WMQWW57N3QRF4RFSJG/ | Mailing List Third Party Advisory |
https://github.com/pikepdf/pikepdf/blob/v2.10.0/docs/release_notes.rst#v2100 | Release Notes Third Party Advisory |
Information
Published : 2021-04-01 13:15
Updated : 2022-12-03 06:25
NVD link : CVE-2021-29421
Mitre link : CVE-2021-29421
JSON object : View
CWE
CWE-611
Improper Restriction of XML External Entity Reference
Products Affected
pikepdf_project
- pikepdf
fedoraproject
- fedora