Restlet Framework 2.1.x before 2.1.7 and 2.x.x before 2.2 RC1, when using XMLRepresentation or XML serializers, allows attackers to cause a denial of service via an XML Entity Expansion (XEE) attack.
{
"cwe_ids": [
"CWE-776"
],
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:21:10Z",
"nvd_published_at": null,
"severity": "MODERATE"
}