PT-2021-18202 · Pypi+1 · Pikepdf+1

Eric Therond

·

Published

2021-04-01

·

Updated

2025-12-12

·

CVE-2021-29421

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: pikepdf versions 1.3.0 through 2.9.2
Description: The issue allows XXE (XML External Entity) attacks when parsing XMP metadata entries in the models/metadata.py file of the pikepdf package for Python. This occurs due to improper handling of XML external entities, potentially leading to data exposure or other security issues.
Recommendations: For pikepdf versions 1.3.0 through 2.9.2, update to a version that contains a fix for this issue to prevent XXE attacks when parsing XMP metadata entries. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2030
CVE-2021-29421
GHSA-CCGM-3XW4-H5P8
MGASA-2021-0268
OPENSUSE-SU-2024:11250-1
OPENSUSE-SU-2024:13864-1
PYSEC-2021-34

Affected Products

Alt Linux
Pikepdf