Restlet Framework 2.1.x before 2.1.7 and 2.x.x before 2.2 RC1, when using XMLRepresentation or XML serializers, allows attackers to cause a denial of service via an XML Entity Expansion (XEE) attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Restlet_framework | Restlet | * | 2.2 (including) |
Restlet_framework | Restlet | 2.1.0 (including) | 2.1.0 (including) |
Restlet_framework | Restlet | 2.1.1 (including) | 2.1.1 (including) |
Restlet_framework | Restlet | 2.1.2 (including) | 2.1.2 (including) |
Restlet_framework | Restlet | 2.1.3 (including) | 2.1.3 (including) |
Restlet_framework | Restlet | 2.1.4 (including) | 2.1.4 (including) |
Restlet_framework | Restlet | 2.1.5 (including) | 2.1.5 (including) |
Restlet_framework | Restlet | 2.1.6 (including) | 2.1.6 (including) |
Restlet_framework | Restlet | 2.2-milestone1 (including) | 2.2-milestone1 (including) |
Restlet_framework | Restlet | 2.2-milestone2 (including) | 2.2-milestone2 (including) |
Restlet_framework | Restlet | 2.2-milestone3 (including) | 2.2-milestone3 (including) |
Restlet_framework | Restlet | 2.2-milestone4 (including) | 2.2-milestone4 (including) |
Restlet_framework | Restlet | 2.2-milestone5 (including) | 2.2-milestone5 (including) |
Restlet | Ubuntu | artful | * |
Restlet | Ubuntu | bionic | * |
Restlet | Ubuntu | cosmic | * |
Restlet | Ubuntu | esm-apps/bionic | * |
Restlet | Ubuntu | esm-apps/xenial | * |
Restlet | Ubuntu | quantal | * |
Restlet | Ubuntu | saucy | * |
Restlet | Ubuntu | trusty | * |
Restlet | Ubuntu | upstream | * |
Restlet | Ubuntu | utopic | * |
Restlet | Ubuntu | vivid | * |
Restlet | Ubuntu | wily | * |
Restlet | Ubuntu | xenial | * |
Restlet | Ubuntu | yakkety | * |
Restlet | Ubuntu | zesty | * |