Vulnerabilities > Restlet > Restlet > 2.3.11

DATE CVE VULNERABILITY TITLE RISK
2017-11-30 CVE-2017-14949 XXE vulnerability in Restlet
Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered.
network
low complexity
restlet CWE-611
5.0