← Back

CVE-2023-0482

nvd nist
Published: Feb 17, 2023Modified: Mar 18, 2025

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.

Affected (8)

1 product
Resteasy
2 products
Active Iq Unified Manager
Oncommand Workflow Automation
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 3.15.4
Version 4.7.7
Version 5.0.5
Version 6.2.2
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Netapp
All versions
All versions
All versions
All versions

References (4)

Timeline

No history available yet.