CVE Vulnerabilities

CVE-2023-0482

Creation of Temporary File With Insecure Permissions

Published: Feb 17, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Ubuntu
MEDIUM

In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.

Weakness

Opening temporary files without appropriate measures or controls can leave the file, its contents and any function that it impacts vulnerable to attack.

Affected Software

Name Vendor Start Version End Version
Resteasy Redhat * 4.7.8 (excluding)
AMQ Broker 7.10.3 RedHat RESTEasy *
EAP 7.4.10 release RedHat RESTEasy *
MTA-6.1-RHEL-8 RedHat mta/mta-hub-rhel8:6.1.4-2 *
MTA-6.1-RHEL-8 RedHat mta/mta-operator-bundle:6.1.4-3 *
MTA-6.1-RHEL-8 RedHat mta/mta-pathfinder-rhel8:6.1.4-1 *
MTA-6.1-RHEL-8 RedHat mta/mta-rhel8-operator:6.1.4-3 *
MTA-6.1-RHEL-8 RedHat mta/mta-ui-rhel8:6.1.4-2 *
MTA-6.1-RHEL-8 RedHat mta/mta-windup-addon-rhel8:6.1.4-2 *
Red Hat AMQ Streams 2.5.0 RedHat *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-resteasy-0:3.15.5-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-resteasy-0:3.15.5-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-resteasy-0:3.15.5-1.Final_redhat_00001.1.el7eap *
Red Hat Single Sign-On 7 RedHat RESTEasy *
Red Hat Single Sign-On 7.6 for RHEL 7 RedHat rh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el7sso *
Red Hat Single Sign-On 7.6 for RHEL 8 RedHat rh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el8sso *
Red Hat Single Sign-On 7.6 for RHEL 9 RedHat rh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el9sso *
RHEL-8 based Middleware Containers RedHat rh-sso-7/sso76-openshift-rhel8:7.6-22 *
RHPAM 7.13.4 async RedHat RESTEasy *
RHPAM 7.13.5 async RedHat RESTEasy *
Resteasy Ubuntu devel *
Resteasy Ubuntu esm-apps/focal *
Resteasy Ubuntu esm-apps/jammy *
Resteasy Ubuntu esm-apps/noble *
Resteasy Ubuntu esm-apps/xenial *
Resteasy Ubuntu focal *
Resteasy Ubuntu jammy *
Resteasy Ubuntu kinetic *
Resteasy Ubuntu lunar *
Resteasy Ubuntu mantic *
Resteasy Ubuntu noble *
Resteasy Ubuntu oracular *
Resteasy Ubuntu trusty *
Resteasy Ubuntu upstream *
Resteasy Ubuntu xenial *
Resteasy3.0 Ubuntu bionic *
Resteasy3.0 Ubuntu devel *
Resteasy3.0 Ubuntu esm-apps/bionic *
Resteasy3.0 Ubuntu esm-apps/focal *
Resteasy3.0 Ubuntu esm-apps/jammy *
Resteasy3.0 Ubuntu esm-apps/noble *
Resteasy3.0 Ubuntu focal *
Resteasy3.0 Ubuntu jammy *
Resteasy3.0 Ubuntu kinetic *
Resteasy3.0 Ubuntu lunar *
Resteasy3.0 Ubuntu mantic *
Resteasy3.0 Ubuntu noble *
Resteasy3.0 Ubuntu oracular *
Resteasy3.0 Ubuntu trusty *
Resteasy3.0 Ubuntu upstream *
Resteasy3.0 Ubuntu xenial *

Potential Mitigations

References