CVE-2023-0481 Information

Description

In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.

Reference

https://github.com/quarkusio/quarkus/pull/30694

Share on: