In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.jboss.resteasy:resteasy-core(Maven) | 6.0.0.Beta1 | 6.2.3.Final | N/A |
| org.jboss.resteasy:resteasy-core(Maven) | 5.0.0.Alpha1 | 5.0.6.Final | N/A |
| org.jboss.resteasy:resteasy-core(Maven) | 4.0.0.Beta1 | 4.7.8.Final | N/A |
| org.jboss.resteasy:resteasy-multipart-provider(Maven) | 6.0.0.Beta1 | 6.2.3.Final | N/A |
| org.jboss.resteasy:resteasy-multipart-provider(Maven) | 5.0.0.Alpha1 | 5.0.6.Final | N/A |
| org.jboss.resteasy:resteasy-multipart-provider(Maven) | 4.0.0.Beta1 | 4.7.8.Final | N/A |
| org.jboss.resteasy:resteasy-multipart-provider(Maven) | 0 | 3.15.5.Final | N/A |
| org.jboss.resteasy:resteasy-core(Maven) | 0 | 3.15.5.Final | N/A |
CVSS Metrics