CVE-2021-29421 log
Source |
|
Severity | Medium |
Remote | Yes |
Type | Xml external entity injection |
Description | models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XML external entity injection (XXE) when parsing XMP metadata entries. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-1761 | python-pikepdf | 2.9.2-1 | 2.10.0-1 | Medium | Fixed |
References |
---|
https://portswigger.net/web-security/xxe https://github.com/pikepdf/pikepdf/commit/3f38f73218e5e782fe411ccbb3b44a793c0b343a |