CVE-2017-14868: Restlet
High severity, CVSS 7.5. EPSS: 2.5% chance of exploitation in the next 30 days.
Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request. This affects use of the Jax-rs extension.
Affected products
- Restlet Restlet: before 2.3.11 (fixed in 2.3.11)
Published 2017-11-30. Last modified 2026-06-17.