Bug 1520471 (CVE-2017-14949) - CVE-2017-14949 restlet: XXE vulnerability in XML extension allows remote attackers to access arbitrary files via a crafted REST API HTTP request
Summary: CVE-2017-14949 restlet: XXE vulnerability in XML extension allows remote atta...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2017-14949
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1520472
Blocks: 1520474
TreeView+ depends on / blocked
 
Reported: 2017-12-04 14:34 UTC by Adam Mariš
Modified: 2021-10-21 11:57 UTC (History)
11 users (show)

Fixed In Version: restlet 2.3.12
Clone Of:
Environment:
Last Closed: 2021-10-21 11:57:41 UTC
Embargoed:


Attachments (Terms of Use)

Description Adam Mariš 2017-12-04 14:34:41 UTC
Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered. This is related to XmlRepresentation, DOMRepresentation, SaxRepresentation, and JacksonRepresentation.

External References:

https://github.com/restlet/restlet-framework-java/wiki/XEE-security-enhancements#vulnerability-cve-2017-14949

Comment 1 Adam Mariš 2017-12-04 14:35:05 UTC
Created restlet-jse tracking bugs for this issue:

Affects: fedora-all [bug 1520472]


Note You need to log in before you can comment on or make changes to this bug.