Description
In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.
Remediation
References
https://github.com/quarkusio/quarkus/pull/30694
Related Vulnerabilities
CVE-2020-36649 Vulnerability in maven package org.webjars.bower:papaparse
CVE-2015-20110 Vulnerability in npm package generator-jhipster
CVE-2023-30513 Vulnerability in maven package org.csanchez.jenkins.plugins:kubernetes
CVE-2023-37911 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2022-24898 Vulnerability in maven package org.xwiki.commons:xwiki-commons-xml