Description
In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.
Remediation
References
https://github.com/quarkusio/quarkus/pull/30694
Related Vulnerabilities
CVE-2023-46122 Vulnerability in maven package org.scala-sbt:sbt
CVE-2023-40014 Vulnerability in npm package @openzeppelin/contracts
CVE-2020-36650 Vulnerability in npm package gry
CVE-2020-8929 Vulnerability in maven package com.google.crypto.tink:tink
CVE-2023-29528 Vulnerability in maven package org.xwiki.commons:xwiki-commons-xml