Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-0482


In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.


Published

2023-02-17T22:15:11.957

Last Modified

2025-03-18T16:15:15.277

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-378
  • Type: Secondary
    NVD-CWE-Other
  • Type: Secondary
    CWE-378

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat resteasy 3.15.4 Yes
Application redhat resteasy 4.7.7 Yes
Application redhat resteasy 5.0.5 Yes
Application redhat resteasy 6.2.2 Yes
Application netapp active_iq_unified_manager - Yes
Application netapp active_iq_unified_manager - Yes
Application netapp active_iq_unified_manager - Yes
Application netapp oncommand_workflow_automation - Yes

References