VDB

DEBIAN-CVE-2023-0482

DEBIAN-CVE-2023-0482 PUBLISHED CVSS 5.5 MEDIUM

In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.

Risk Scores

CVSS v3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Debian:13resteasy3.03.0.26-6, 0, 3.0.26-6
Debian:14resteasy3.03.0.26-6, 3.0.26-6, 0
Debian:12resteasy3.00, 0, 3.0.26-6
Debian:11resteasy3.00, 0, 3.0.26-2

Timeline

  • Feb 17, 2023 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›