Red Hat Bugzilla – Bug 999809
CVE-2012-2656 Restlet: XML eXternal Entity (XXE) flaw
Last modified: 2014-10-20 20:05:22 EDT
It was found that Restlet is vulnerable to XXE (XML eXternal Entity) attacks. If a Restlet endpoint using XML transport, a user can submit a request containing an external XML entity. This XML entity will be resolved, allowing a remote attacker to read files in the context of the user running the application server.
Not Vulnerable. This issue does not affect the versions of Restlet as shipped with various Red Hat products.