GHSA-2mp8-qvqm-3xwq
Dashboard / Vulnerabilities / GHSA-2mp8-qvqm-3xwq
Summary: Restlet Framework Ja-rs extension is vulnerable to XXE when using SimpleXMLProvider
Details: Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request. This affects use of the Jax-rs extension.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-14868, https://github.com/restlet/restlet-framework-java/issues/1286, https://github.com/advisories/GHSA-2mp8-qvqm-3xwq, https://github.com/restlet/restlet-framework-java, https://github.com/restlet/restlet-framework-java/wiki/XEE-security-enhancements, https://lgtm.com/blog/restlet_CVE-2017-14868
Affected packages
Package
Name: org.restlet.jse:org.restlet.ext.jaxrs
Purl: pkg:maven/org.restlet.jse/org.restlet.ext.jaxrs
Affected ranges
Type: ECOSYSTEM
Events:
