CVE-2021-29421 log

Source
Severity Medium
Remote Yes
Type Xml external entity injection
Description
models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XML external entity injection (XXE) when parsing XMP metadata entries.
Group Package Affected Fixed Severity Status Ticket
AVG-1761 python-pikepdf 2.9.2-1 2.10.0-1 Medium Fixed
References
https://portswigger.net/web-security/xxe
https://github.com/pikepdf/pikepdf/commit/3f38f73218e5e782fe411ccbb3b44a793c0b343a