models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0166 | models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries. |
Github GHSA |
GHSA-ccgm-3xw4-h5p8 | Improper Restriction of XML External Entity Reference in pikepdf |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 28 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Thu, 22 May 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T22:02:51.995Z
Reserved: 2021-03-29T00:00:00
Link: CVE-2021-29421
No data.
Status : Modified
Published: 2021-04-01T20:15:12.453
Modified: 2024-11-21T06:01:03.820
Link: CVE-2021-29421
OpenCVE Enrichment
No data.
EUVD
Github GHSA