QID 983786
QID 983786: Java (maven) Security Update for org.restlet.jse:org.restlet (GHSA-2mp8-qvqm-3xwq)
Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request. This affects use of the Jax-rs extension.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2mp8-qvqm-3xwq for updates pertaining to this vulnerability.
Vendor References
- GHSA-2mp8-qvqm-3xwq -
github.com/advisories/GHSA-2mp8-qvqm-3xwq
CVEs related to QID 983786
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2mp8-qvqm-3xwq | org.restlet.jse:org.restlet |
|