VDB
DEBIAN-CVE-2023-0482
DEBIAN-CVE-2023-0482
PUBLISHED
CVSS 5.5 MEDIUM
In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
Risk Scores
CVSS v3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:13 | resteasy3.0 | 3.0.26-6, 0, 3.0.26-6 |
| Debian:14 | resteasy3.0 | 3.0.26-6, 3.0.26-6, 0 |
| Debian:12 | resteasy3.0 | 0, 0, 3.0.26-6 |
| Debian:11 | resteasy3.0 | 0, 0, 3.0.26-2 |
Timeline
- Feb 17, 2023 CVE Published
- Apr 28, 2026 CVE Updated