ZeroHour

CVE-2023-0482

CVSS 3.1
5.5 medium
EPSS
<1%p19
Published
()
Modified
Description

In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.

Vendors
redhatnetapp
Products
resteasy, active iq unified manager, oncommand workflow automation
Weakness
CWE-378
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.