QID 980634
QID 980634: Python (pip) Security Update for pikepdf (GHSA-ccgm-3xw4-h5p8)
models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-ccgm-3xw4-h5p8 for updates pertaining to this vulnerability.
Vendor References
- GHSA-ccgm-3xw4-h5p8 -
github.com/advisories/GHSA-ccgm-3xw4-h5p8
CVEs related to QID 980634
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-ccgm-3xw4-h5p8 | pikepdf |
|