CVE Vulnerabilities

CVE-2023-0482

Creation of Temporary File With Insecure Permissions

Published: Feb 17, 2023 | Modified: Mar 18, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.

Weakness

Opening temporary files without appropriate measures or controls can leave the file, its contents and any function that it impacts vulnerable to attack.

Affected Software

NameVendorStart VersionEnd Version
ResteasyRedhat3.15.4 (including)3.15.4 (including)
ResteasyRedhat4.7.7 (including)4.7.7 (including)
ResteasyRedhat5.0.5 (including)5.0.5 (including)
ResteasyRedhat6.2.2 (including)6.2.2 (including)
AMQ Broker 7.10.3RedHatRESTEasy*
MTA-6.1-RHEL-8RedHatmta/mta-hub-rhel8:6.1.4-2*
MTA-6.1-RHEL-8RedHatmta/mta-operator-bundle:6.1.4-3*
MTA-6.1-RHEL-8RedHatmta/mta-pathfinder-rhel8:6.1.4-1*
MTA-6.1-RHEL-8RedHatmta/mta-rhel8-operator:6.1.4-3*
MTA-6.1-RHEL-8RedHatmta/mta-ui-rhel8:6.1.4-2*
MTA-6.1-RHEL-8RedHatmta/mta-windup-addon-rhel8:6.1.4-2*
Red Hat AMQ Streams 2.5.0RedHat*
Red Hat JBoss Enterprise Application Platform 7RedHatRESTEasy*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-resteasy-0:3.15.5-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-resteasy-0:3.15.5-1.Final_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-resteasy-0:3.15.5-1.Final_redhat_00001.1.el7eap*
Red Hat Single Sign-On 7RedHatRESTEasy*
Red Hat Single Sign-On 7.6 for RHEL 7RedHatrh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el7sso*
Red Hat Single Sign-On 7.6 for RHEL 8RedHatrh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el8sso*
Red Hat Single Sign-On 7.6 for RHEL 9RedHatrh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el9sso*
RHEL-8 based Middleware ContainersRedHatrh-sso-7/sso76-openshift-rhel8:7.6-22*
RHPAM 7.13.4 asyncRedHatRESTEasy*
RHPAM 7.13.5 asyncRedHatRESTEasy*
ResteasyUbuntudevel*
ResteasyUbuntuesm-apps/focal*
ResteasyUbuntuesm-apps/jammy*
ResteasyUbuntuesm-apps/noble*
ResteasyUbuntuesm-apps/xenial*
ResteasyUbuntufocal*
ResteasyUbuntujammy*
ResteasyUbuntukinetic*
ResteasyUbuntulunar*
ResteasyUbuntumantic*
ResteasyUbuntunoble*
ResteasyUbuntuoracular*
ResteasyUbuntuplucky*
ResteasyUbuntuquesting*
ResteasyUbuntutrusty*
ResteasyUbuntuupstream*
ResteasyUbuntuxenial*
Resteasy3.0Ubuntubionic*
Resteasy3.0Ubuntudevel*
Resteasy3.0Ubuntuesm-apps/bionic*
Resteasy3.0Ubuntuesm-apps/focal*
Resteasy3.0Ubuntuesm-apps/jammy*
Resteasy3.0Ubuntuesm-apps/noble*
Resteasy3.0Ubuntufocal*
Resteasy3.0Ubuntujammy*
Resteasy3.0Ubuntukinetic*
Resteasy3.0Ubuntulunar*
Resteasy3.0Ubuntumantic*
Resteasy3.0Ubuntunoble*
Resteasy3.0Ubuntuoracular*
Resteasy3.0Ubuntuplucky*
Resteasy3.0Ubuntuquesting*
Resteasy3.0Ubuntutrusty*
Resteasy3.0Ubuntuupstream*
Resteasy3.0Ubuntuxenial*

Potential Mitigations

References