In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
10 Feb 2025, 13:12
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:* cpe:2.3:a:redhat:resteasy:5.0.5:*:*:*:*:*:*:* cpe:2.3:a:redhat:resteasy:6.2.2:*:*:*:*:*:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* cpe:2.3:a:redhat:resteasy:4.7.7:*:*:*:*:*:*:* cpe:2.3:a:redhat:resteasy:3.15.4:*:*:*:*:*:*:* |
|
References | () https://security.netapp.com/advisory/ntap-20230427-0001/ - Third Party Advisory | |
First Time |
Netapp oncommand Workflow Automation
Netapp Netapp active Iq Unified Manager |
21 Nov 2024, 07:37
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/resteasy/resteasy/pull/3409/commits/807d7456f2137cde8ef7c316707211bf4e542d56 - Patch | |
References | () https://security.netapp.com/advisory/ntap-20230427-0001/ - |
Information
Published : 2023-02-17 22:15
Updated : 2025-03-18 16:15
NVD link : CVE-2023-0482
Mitre link : CVE-2023-0482
CVE.ORG link : CVE-2023-0482
JSON object : View
Products Affected
netapp
- active_iq_unified_manager
- oncommand_workflow_automation
redhat
- resteasy
CWE