GHSA-2mp8-qvqm-3xwq
HIGHCVE-2017-14868Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request. This affects use of the Jax-rs extension.
- Affected
- < 2.3.11
- Fixed in
- 2.3.11
- Weakness
- CWE-611
- Published
- 2018-10-17
- Source
- github