Description
Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request. This affects use of the Jax-rs extension.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0478 | Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request. This affects use of the Jax-rs extension. |
Github GHSA |
GHSA-2mp8-qvqm-3xwq | Restlet Framework Ja-rs extension is vulnerable to XXE when using SimpleXMLProvider |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T19:42:21.581Z
Reserved: 2017-09-28T00:00:00.000Z
Link: CVE-2017-14868
No data.
Status : Modified
Published: 2017-11-30T18:29:00.243
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-14868
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA