First published: Mon Jan 23 2023(Updated: )
In Quarkus' RESTEasy Reactive component, usage of File.createTempFile() class in the FileBodyHandler class causes temp files to be created with -rw-r--r-- permissions.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Quarkus Quarkus | <2.16.1 | |
maven/io.quarkus.resteasy.reactive:resteasy-reactive-common | <3.0.0.Alpha4 | 3.0.0.Alpha4 |
redhat/quarkus | <2.16.1 | 2.16.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-0481.
The title of this vulnerability is 'In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.'
The severity of CVE-2023-0481 is low, with a severity value of 3.3.
The Quarkus software version up to 2.16.1 is affected by CVE-2023-0481.
To fix CVE-2023-0481, you should upgrade Quarkus to a version higher than 2.16.1.