Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-0482

Опубликовано: 17 фев. 2023
Источник: debian
EPSS Низкий

Описание

In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
resteasyunfixedpackage
resteasy3.0unfixedpackage
resteasy3.0ignoredbookwormpackage
resteasy3.0no-dsabullseyepackage
resteasy3.0no-dsabusterpackage

Примечания

  • https://github.com/resteasy/resteasy/pull/3409/

  • https://github.com/resteasy/resteasy/commit/3d8a551d80b98f185edaff6f895188ec8211366b

EPSS

Процентиль: 9%
0.00037
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.

CVSS3: 5.3
redhat
больше 2 лет назад

In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.

CVSS3: 5.5
nvd
больше 2 лет назад

In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.

CVSS3: 5.5
redos
9 дней назад

Уязвимость resteasy

CVSS3: 5.5
github
7 месяцев назад

Insecure Temporary File in RESTEasy

EPSS

Процентиль: 9%
0.00037
Низкий