5
CVSSv2

CVE-2017-14949

Published: 30/11/2017 Updated: 15/12/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Restlet Framework prior to 2.3.12 allows remote malicious users to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered. This is related to XmlRepresentation, DOMRepresentation, SaxRepresentation, and JacksonRepresentation.

Vulnerable Product Search on Vulmon Subscribe to Product

restlet restlet

Vendor Advisories

Restlet Framework before 2312 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered This is related to XmlRepresentation, DOMRepresentation, SaxRepresentation, and JacksonRepresentation ...