Related Vulnerabilities: CVE-2021-29421  

models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XML external entity injection (XXE) when parsing XMP metadata entries.

Severity Medium

Remote Yes

Type Xml external entity injection

Description

models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XML external entity injection (XXE) when parsing XMP metadata entries.

AVG-1761 python-pikepdf 2.9.2-1 2.10.0-1 Medium Fixed

https://portswigger.net/web-security/xxe
https://github.com/pikepdf/pikepdf/commit/3f38f73218e5e782fe411ccbb3b44a793c0b343a