Description
In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.
Remediation
References
https://github.com/quarkusio/quarkus/pull/30694
Related Vulnerabilities
CVE-2021-33420 Vulnerability in npm package replicator
CVE-2013-4152 Vulnerability in maven package org.springframework:spring-oxm
CVE-2021-3461 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2018-1288 Vulnerability in maven package org.apache.kafka:kafka_2.12
CVE-2023-45648 Vulnerability in maven package org.apache.tomcat:tomcat-coyote