Skip to content

Moderate severity vulnerability that affects org.restlet.jse:org.restlet

Moderate severity GitHub Reviewed Published Oct 17, 2018 to the GitHub Advisory Database • Updated Jan 9, 2023

Package

maven org.restlet.jse:org.restlet (Maven)

Affected versions

>= 2.1.0, < 2.1.7

Patched versions

2.1.7

Description

Restlet Framework 2.1.x before 2.1.7 and 2.x.x before 2.2 RC1, when using XMLRepresentation or XML serializers, allows attackers to cause a denial of service via an XML Entity Expansion (XEE) attack.

References

Published to the GitHub Advisory Database Oct 17, 2018
Reviewed Jun 16, 2020
Last updated Jan 9, 2023

Severity

Moderate

EPSS score

0.240%
(62nd percentile)

Weaknesses

CVE ID

CVE-2014-1868

GHSA ID

GHSA-73cq-fhp3-8rpw
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.