Restlet Framework Ja-rs extension is vulnerable to XXE when using SimpleXMLProvider
High severity
GitHub Reviewed
Published
Oct 17, 2018
to the GitHub Advisory Database
•
Updated Sep 26, 2023
Package
Affected versions
< 2.3.11
Patched versions
2.3.11
Description
Published to the GitHub Advisory Database
Oct 17, 2018
Reviewed
Jun 16, 2020
Last updated
Sep 26, 2023
Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request. This affects use of the Jax-rs extension.
References