Medium severity5.5NVD Advisory· Published Feb 17, 2023· Updated Jun 17, 2026
CVE-2023-0482
CVE-2023-0482
Description
In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jboss.resteasy:resteasy-coreMaven | >= 6.0.0.Beta1, < 6.2.3.Final | 6.2.3.Final |
org.jboss.resteasy:resteasy-coreMaven | >= 5.0.0.Alpha1, < 5.0.6.Final | 5.0.6.Final |
org.jboss.resteasy:resteasy-coreMaven | >= 4.0.0.Beta1, < 4.7.8.Final | 4.7.8.Final |
org.jboss.resteasy:resteasy-multipart-providerMaven | >= 6.0.0.Beta1, < 6.2.3.Final | 6.2.3.Final |
org.jboss.resteasy:resteasy-multipart-providerMaven | >= 5.0.0.Alpha1, < 5.0.6.Final | 5.0.6.Final |
org.jboss.resteasy:resteasy-multipart-providerMaven | >= 4.0.0.Beta1, < 4.7.8.Final | 4.7.8.Final |
org.jboss.resteasy:resteasy-multipart-providerMaven | < 3.15.5.Final | 3.15.5.Final |
org.jboss.resteasy:resteasy-coreMaven | < 3.15.5.Final | 3.15.5.Final |
Affected products
11cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*+ 2 more
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
- cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
- RESTEasy/RESTEasydescription
- ghsa-coords2 versions
>= 6.0.0.Beta1, < 6.2.3.Final+ 1 more
- (no CPE)range: >= 6.0.0.Beta1, < 6.2.3.Final
- (no CPE)range: >= 6.0.0.Beta1, < 6.2.3.Final
Patches
Vulnerability mechanics
References
13- github.com/resteasy/resteasy/pull/3409/commits/807d7456f2137cde8ef7c316707211bf4e542d56nvdPatchWEB
- github.com/advisories/GHSA-2c6g-pfx3-w7h8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-0482ghsaADVISORY
- security.netapp.com/advisory/ntap-20230427-0001/nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cgighsaWEB
- github.com/resteasy/resteasy/pull/3409ghsaWEB
- github.com/resteasy/resteasy/pull/3410ghsaWEB
- github.com/resteasy/resteasy/pull/3412ghsaWEB
- github.com/resteasy/resteasy/pull/3413ghsaWEB
- github.com/resteasy/resteasy/pull/3423ghsaWEB
- github.com/resteasy/resteasy/security/advisories/GHSA-2c6g-pfx3-w7h8ghsaWEB
- issues.redhat.com/browse/RESTEASY-3286ghsaWEB
- security.netapp.com/advisory/ntap-20230427-0001ghsaWEB
News mentions
0No linked articles in our index yet.