Description
In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.
Remediation
References
https://github.com/quarkusio/quarkus/pull/30694
Related Vulnerabilities
CVE-2022-24740 Vulnerability in npm package @plone/volto
CVE-2022-37616 Vulnerability in npm package @xmldom/xmldom
CVE-2016-5018 Vulnerability in maven package tomcat:jasper-runtime
CVE-2023-46651 Vulnerability in maven package io.jenkins.plugins:warnings-ng
CVE-2020-36049 Vulnerability in maven package org.webjars.npm:socket.io-parser