In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
10 Feb 2025, 13:12
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:* cpe:2.3:a:redhat:resteasy:6.2.2:*:*:*:*:*:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* cpe:2.3:a:redhat:resteasy:5.0.5:*:*:*:*:*:*:* cpe:2.3:a:redhat:resteasy:3.15.4:*:*:*:*:*:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:* cpe:2.3:a:redhat:resteasy:4.7.7:*:*:*:*:*:*:* |
|
First Time |
Netapp
Netapp oncommand Workflow Automation Netapp active Iq Unified Manager |
|
References | () https://security.netapp.com/advisory/ntap-20230427-0001/ - Third Party Advisory |
21 Nov 2024, 07:37
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/resteasy/resteasy/pull/3409/commits/807d7456f2137cde8ef7c316707211bf4e542d56 - Patch | |
References | () https://security.netapp.com/advisory/ntap-20230427-0001/ - |
27 Apr 2023, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
01 Mar 2023, 13:44
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:redhat:resteasy:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
References | (MISC) https://github.com/resteasy/resteasy/pull/3409/commits/807d7456f2137cde8ef7c316707211bf4e542d56 - Patch | |
CWE | NVD-CWE-Other |
21 Feb 2023, 14:50
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-02-17 22:15
Updated : 2025-03-18 16:15
NVD link : CVE-2023-0482
Mitre link : CVE-2023-0482
CVE.ORG link : CVE-2023-0482
JSON object : View
Products Affected
redhat
- resteasy
netapp
- active_iq_unified_manager
- oncommand_workflow_automation
CWE