GHSA-x58j-j539-w8mv

Suggest an improvement
Source
https://github.com/advisories/GHSA-x58j-j539-w8mv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/10/GHSA-x58j-j539-w8mv/GHSA-x58j-j539-w8mv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-x58j-j539-w8mv
Aliases
  • CVE-2021-46849
Withdrawn
2023-08-03T22:53:44Z
Published
2022-10-24T19:00:20Z
Modified
2026-09-10T03:49:46Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Duplicate Advisory: Improper Restriction of XML External Entity Reference in pikepdf
Details

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-29421, GHSA-ccgm-3xw4-h5p8. Reason: This candidate is a duplicate of CVE-2021-29421. Notes: All CVE users should reference CVE-2021-29421 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

Database specific
{
    "cwe_ids":  [
        "CWE-611"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-08-03T22:53:44Z",
    "nvd_published_at":  "2022-10-24T14:15:00Z",
    "severity":  "CRITICAL"
}
References

Affected packages

PyPI / pikepdf

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.2.0
Fixed
2.10.0

Affected versions

1.*
1.2.0
1.3.0
1.3.1
1.4.0
1.5.0.post0
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.11.0
1.11.1
1.11.2
1.12.0
1.13.0
1.14.0
1.15.0
1.15.1
1.16.0
1.16.1
1.17.0
1.17.1
1.17.2
1.17.3
1.18.0
1.19.0
1.19.1
1.19.2
1.19.3
1.19.4
2.*
2.0.0
2.1.0
2.1.1
2.1.2
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
2.8.0
2.8.0.post2
2.9.0
2.9.1
2.9.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/10/GHSA-x58j-j539-w8mv/GHSA-x58j-j539-w8mv.json"