models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-04-01T00:00:00

Updated: 2024-08-03T22:02:51.995Z

Reserved: 2021-03-29T00:00:00

Link: CVE-2021-29421

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-01T20:15:12.453

Modified: 2024-11-21T06:01:03.820

Link: CVE-2021-29421

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-04-01T00:00:00Z

Links: CVE-2021-29421 - Bugzilla