models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
References
Configurations
History
No history.
Information
Published : 2021-04-01 20:15
Updated : 2023-11-07 03:32
NVD link : CVE-2021-29421
Mitre link : CVE-2021-29421
CVE.ORG link : CVE-2021-29421
JSON object : View
Products Affected
pikepdf_project
- pikepdf
fedoraproject
- fedora
CWE
CWE-611
Improper Restriction of XML External Entity Reference