CVE-2021-29421 log
| Source |
|
| Severity | Medium |
| Remote | Yes |
| Type | Xml external entity injection |
| Description | models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XML external entity injection (XXE) when parsing XMP metadata entries. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-1761 | python-pikepdf | 2.9.2-1 | 2.10.0-1 | Medium | Fixed |
| References |
|---|
https://portswigger.net/web-security/xxe https://github.com/pikepdf/pikepdf/commit/3f38f73218e5e782fe411ccbb3b44a793c0b343a |