Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j75r-vf64-6rrh

Опубликовано: 24 фев. 2023
Источник: github
Github: Прошло ревью
CVSS3: 3.3

Описание

RestEasy Reactive implementation of Quarkus allows Creation of Temporary File With Insecure Permissions

In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.

Пакеты

Наименование

io.quarkus.resteasy.reactive:resteasy-reactive-common

maven
Затронутые версииВерсия исправления

< 3.0.0.Alpha4

3.0.0.Alpha4

EPSS

Процентиль: 12%
0.0004
Низкий

3.3 Low

CVSS3

Дефекты

CWE-378
CWE-668

Связанные уязвимости

CVSS3: 5.3
redhat
около 3 лет назад

In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.

CVSS3: 3.3
nvd
почти 3 года назад

In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.

EPSS

Процентиль: 12%
0.0004
Низкий

3.3 Low

CVSS3

Дефекты

CWE-378
CWE-668