Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request. This affects use of the Jax-rs extension.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Restlet Framework 安全漏洞
Vulnerability Description
Restlet Framework是美国Restlet公司的一个轻量级的REST框架。该框架能够将Web站点和Web服务组装到一个统一的Web应用程序中。 Restlet Framework 2.3.11之前的版本中存在安全漏洞。远程攻击者可通过发送带有特制的XML数据的请求利用该漏洞访问任意文件。
CVSS Information
N/A
Vulnerability Type
N/A