Vulnerability Details CVE-2023-0482
In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 9.9%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2023-0482
-
cpe:2.3:a:netapp:active_iq_unified_manager:-
-
cpe:2.3:a:netapp:oncommand_workflow_automation:-
-
cpe:2.3:a:redhat:resteasy:3.15.4
-
cpe:2.3:a:redhat:resteasy:4.7.7
-
cpe:2.3:a:redhat:resteasy:5.0.5
-
cpe:2.3:a:redhat:resteasy:6.2.2