← Back

CVE-2014-1868

nvd nist
Published: Oct 6, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Restlet Framework 2.1.x before 2.1.7 and 2.x.x before 2.2 RC1, when using XMLRepresentation or XML serializers, allows attackers to cause a denial of service via an XML Entity Expansion (XEE) attack.

Affected (13)

1 product
Restlet Framework
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Restlet
Up to 2.2
Version 2.1.0
Version 2.1.1
Version 2.1.2
Version 2.1.3
Version 2.1.4
Version 2.1.5
Version 2.1.6
Version 2.2 milestone1
Version 2.2 milestone2
Version 2.2 milestone3
Version 2.2 milestone4
Version 2.2 milestone5

Timeline

No history available yet.