CVE-2021-29421
published 2021-04-01CVE-2021-29421: models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.71%
75.1th percentile
models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pikepdf | < pikepdf 1.17.3+dfsg-5 (bookworm) | pikepdf 1.17.3+dfsg-5 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| pikepdf_project | pikepdf | >= 0 < 1.17.3+dfsg-5 | 1.17.3+dfsg-5 |
| pikepdf_project | pikepdf | >= 0 < 1.17.3+dfsg-5 | 1.17.3+dfsg-5 |
| pikepdf_project | pikepdf | >= 0 < 1.17.3+dfsg-5 | 1.17.3+dfsg-5 |
| pikepdf_project | pikepdf | >= 0 < 1.17.3+dfsg-5 | 1.17.3+dfsg-5 |
| pikepdf_project | pikepdf | >= 1.3.0 < 2.10.0 | 2.10.0 |
| pikepdf_project | pikepdf | 1.3.0 – 2.9.2 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Restriction of XML External Entity Reference in pikepdf
ghsa·2021-04-20
CVE-2021-29421 [HIGH] CWE-611 Improper Restriction of XML External Entity Reference in pikepdf
Improper Restriction of XML External Entity Reference in pikepdf
models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
OSV
Improper Restriction of XML External Entity Reference in pikepdf
osv·2021-04-20
CVE-2021-29421 [HIGH] Improper Restriction of XML External Entity Reference in pikepdf
Improper Restriction of XML External Entity Reference in pikepdf
models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
OSV
CVE-2021-29421: models/metadata
osv·2021-04-01·CVSS 7.5
CVE-2021-29421 [HIGH] CVE-2021-29421: models/metadata
models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
Red Hat
pikepdf: XML external entity issue when parsing XMP metadata entries
vendor_redhat·2021-04-01·CVSS 7.5
CVE-2021-29421 [HIGH] CWE-611 pikepdf: XML external entity issue when parsing XMP metadata entries
pikepdf: XML external entity issue when parsing XMP metadata entries
models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
There's a flaw in the pikepdf Python library's XMP metadata parsing functionality. An attacker who is able to submit a crafted PDF file to be processed by pikepdf could trigger an XML External Entity (XXE) injection. The highest threat of this flaw is to confidentiality of data.
Statement: This flaw does not affect any Red Hat shipped commercial products, as pikepdf is not currently shipped.
Debian
CVE-2021-29421: pikepdf - models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows ...
vendor_debian·2021·CVSS 7.5
CVE-2021-29421 [HIGH] CVE-2021-29421: pikepdf - models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows ...
models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
Scope: local
bookworm: resolved (fixed in 1.17.3+dfsg-5)
bullseye: resolved (fixed in 1.17.3+dfsg-5)
forky: resolved (fixed in 1.17.3+dfsg-5)
sid: resolved (fixed in 1.17.3+dfsg-5)
trixie: resolved (fixed in 1.17.3+dfsg-5)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/pikepdf/pikepdf/blob/v2.10.0/docs/release_notes.rst#v2100https://github.com/pikepdf/pikepdf/commit/3f38f73218e5e782fe411ccbb3b44a793c0b343ahttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36P4HTLBJPO524WMQWW57N3QRF4RFSJG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QFLBBYGEDNXJ7FS6PIWTVI4T4BUPGEQ/https://github.com/pikepdf/pikepdf/blob/v2.10.0/docs/release_notes.rst#v2100https://github.com/pikepdf/pikepdf/commit/3f38f73218e5e782fe411ccbb3b44a793c0b343ahttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36P4HTLBJPO524WMQWW57N3QRF4RFSJG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QFLBBYGEDNXJ7FS6PIWTVI4T4BUPGEQ/
2021-04-01
Published