CVE-2023-0482

Aliases:GHSA-2c6g-pfx3-w7h8
Advisory lineage Upstream: 0 Downstream: 10
Modified
Published: 17 Feb 2023, 00:00
Last modified:18 Mar 2025, 16:02

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.05% LOW
0% probability +0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Feb 2023, 00:00
Published
Vulnerability first disclosed
18 Mar 2025, 16:02
Last Modified
Vulnerability information updated

Description

In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.05% Percentile: 16%

Techniques & Countermeasures

  • CWE-378Creation of Temporary File With Insecure Permissions

    Opening temporary files without appropriate measures or controls can leave the file, its contents and any function that it impacts vulnerable to attack.

Affected Systems

  • org.jboss.resteasyresteasy-core

    ≥ 6.0.0.Beta1, < 6.2.3.Final | ≥ 5.0.0.Alpha1, < 5.0.6.Final | ≥ 4.0.0.Beta1, < 4.7.8.Final | < 3.15.5.Final

  • org.jboss.resteasyresteasy-multipart-provider

    ≥ 6.0.0.Beta1, < 6.2.3.Final | ≥ 5.0.0.Alpha1, < 5.0.6.Final | ≥ 4.0.0.Beta1, < 4.7.8.Final | < 3.15.5.Final

  • netappactive_iq_unified_manager

    na

  • netapponcommand_workflow_automation

    na

  • redhatresteasy

    3.15.4 | 4.7.7 | 5.0.5 | 6.2.2

References (16)