Security Advisory

CVE-2017-14949

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-11-30 18:00:00
Last updated 2024-08-05 19:42:22
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered. This is related to XmlRepresentation, DOMRepresentation, SaxRepresentation, and JacksonRepresentation.