Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-0482

Опубликовано: 31 янв. 2023
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2RESTEasyFix deferred
Migration Toolkit for Runtimesorg.keycloak-keycloak-parentAffected
Red Hat A-MQ OnlineRESTEasyFix deferred
Red Hat build of Apicurio Registry 2RESTEasyAffected
Red Hat build of Quarkusorg.jboss.resteasy/resteasy-coreNot affected
Red Hat Data Grid 8RESTEasyNot affected
Red Hat Enterprise Linux 8resteasyFix deferred
Red Hat Enterprise Linux 9resteasyFix deferred
Red Hat Fuse 7RESTEasyFix deferred
Red Hat Integration Camel K 1RESTEasyNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-378
https://bugzilla.redhat.com/show_bug.cgi?id=2166004RESTEasy: creation of insecure temp files

EPSS

Процентиль: 10%
0.00037
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.

CVSS3: 5.5
nvd
больше 2 лет назад

In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.

CVSS3: 5.5
debian
больше 2 лет назад

In RESTEasy the insecure File.createTempFile() is used in the DataSour ...

CVSS3: 5.5
redos
9 дней назад

Уязвимость resteasy

CVSS3: 5.5
github
7 месяцев назад

Insecure Temporary File in RESTEasy

EPSS

Процентиль: 10%
0.00037
Низкий

5.3 Medium

CVSS3