← back
CVE-2023-0482mediumCWE-378

CVE-2023-0482

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.5epss 0.8%
exploitation probability
0.8%top 46% of all CVEs
observed exploitation
nono source reports it
In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · RESTEasy