In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
References
Configurations
History
21 Nov 2024, 07:37
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/resteasy/resteasy/pull/3409/commits/807d7456f2137cde8ef7c316707211bf4e542d56 - Patch | |
References | () https://security.netapp.com/advisory/ntap-20230427-0001/ - |
Information
Published : 2023-02-17 22:15
Updated : 2024-11-21 07:37
NVD link : CVE-2023-0482
Mitre link : CVE-2023-0482
CVE.ORG link : CVE-2023-0482
JSON object : View
Products Affected
redhat
- resteasy
CWE