Bug 999809 (CVE-2012-2656) - CVE-2012-2656 Restlet: XML eXternal Entity (XXE) flaw
Summary: CVE-2012-2656 Restlet: XML eXternal Entity (XXE) flaw
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2012-2656
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-08-22 07:39 UTC by David Jorm
Modified: 2019-09-29 13:07 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-08-22 07:41:14 UTC


Attachments (Terms of Use)

Description David Jorm 2013-08-22 07:39:40 UTC
It was found that Restlet is vulnerable to XXE (XML eXternal Entity) attacks. If a Restlet endpoint using XML transport, a user can submit a request containing an external XML entity. This XML entity will be resolved, allowing a remote attacker to read files in the context of the user running the application server.

Comment 1 David Jorm 2013-08-22 07:41:14 UTC
External References:

http://blog.restlet.com/2012/05/23/restlet-framework-2-1-rc5-and-2-0-14-released/

Statement:

Not Vulnerable. This issue does not affect the versions of Restlet as shipped with various Red Hat products.


Note You need to log in before you can comment on or make changes to this bug.