In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.
References
Link | Resource |
---|---|
https://github.com/quarkusio/quarkus/pull/30694 | Patch Vendor Advisory |
Configurations
Information
Published : 2023-02-24 10:15
Updated : 2023-03-06 17:44
NVD link : CVE-2023-0481
Mitre link : CVE-2023-0481
JSON object : View
CWE
CWE-668
Exposure of Resource to Wrong Sphere
Products Affected
quarkus
- quarkus