CVE-2023-0482

CWE-3789 documents7 sources
Severity
5.5MEDIUM
EPSS
0.1%
top 84.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 17
Latest updateJul 10

Description

In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

Mavenorg.jboss.resteasy:resteasy-core6.0.0.Beta16.2.3.Final+3
Mavenorg.jboss.resteasy:resteasy-multipart-provider6.0.0.Beta16.2.3.Final+3
CVEListV5resteasyFixed in RESTEasy 4.7.8.Final
NVDredhat/resteasy4 versions+3

Patches

🔴Vulnerability Details

4
OSV
Insecure Temporary File in RESTEasy2025-01-15
GHSA
Insecure Temporary File in RESTEasy2025-01-15
CVEList
CVE-2023-0482: In RESTEasy the insecure File2023-02-17
OSV
CVE-2023-0482: In RESTEasy the insecure File2023-02-17

📋Vendor Advisories

4
Ubuntu
RESTEasy vulnerabilities2025-07-10
Ubuntu
RESTEasy vulnerabilities2025-03-13
Red Hat
RESTEasy: creation of insecure temp files2023-01-31
Debian
CVE-2023-0482: resteasy - In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider...2023
CVE-2023-0482 (MEDIUM CVSS 5.5) | In RESTEasy the insecure File.creat | cvebase.io