Insecure File Permissions in RestEasy Reactive Implementation of Quarkus

Insecure File Permissions in RestEasy Reactive Implementation of Quarkus

CVE-2023-0481 · LOW Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.

Learn more about our User Device Pen Test.