Description
In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.
Remediation
References
https://github.com/quarkusio/quarkus/pull/30694
Related Vulnerabilities
CVE-2021-21120 Vulnerability in npm package electron
CVE-2020-11022 Vulnerability in maven package org.webjars.npm:jquery
CVE-2020-13956 Vulnerability in maven package org.apache.httpcomponents:httpclient
CVE-2019-10158 Vulnerability in maven package org.infinispan:infinispan-spring5-embedded
CVE-2022-0219 Vulnerability in maven package io.github.skylot:jadx-core