Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered. This is related to XmlRepresentation, DOMRepresentation, SaxRepresentation, and JacksonRepresentation.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-11-30T18:00:00

Updated: 2024-08-05T19:42:22.379Z

Reserved: 2017-09-29T00:00:00

Link: CVE-2017-14949

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-11-30T18:29:00.290

Modified: 2017-12-15T19:17:51.867

Link: CVE-2017-14949

cve-icon Redhat

Severity : Moderate

Publid Date: 2017-10-02T00:00:00Z

Links: CVE-2017-14949 - Bugzilla