Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered. This is related to XmlRepresentation, DOMRepresentation, SaxRepresentation, and JacksonRepresentation.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Restlet Framework 安全漏洞
Vulnerability Description
Restlet Framework是美国Restlet公司的一个轻量级的REST框架。该框架能够将Web站点和Web服务组装到一个统一的Web应用程序中。 Restlet Framework 2.3.12之前的版本中存在安全漏洞。远程攻击者可借助特制的REST API HTTP请求利用该漏洞访问任意的文件。
CVSS Information
N/A
Vulnerability Type
N/A