QID 983769
QID 983769: Java (maven) Security Update for org.restlet.jse:org.restlet (GHSA-cvj4-g3gx-8vqq)
Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered. This is related to XmlRepresentation, DOMRepresentation, SaxRepresentation, and JacksonRepresentation.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cvj4-g3gx-8vqq for updates pertaining to this vulnerability.
Vendor References
- GHSA-cvj4-g3gx-8vqq -
github.com/advisories/GHSA-cvj4-g3gx-8vqq
CVEs related to QID 983769
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cvj4-g3gx-8vqq | org.restlet.jse:org.restlet |
|