Description
In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.
Remediation
References
https://github.com/quarkusio/quarkus/pull/30694
Related Vulnerabilities
CVE-2023-48631 Vulnerability in npm package @adobe/css-tools
CVE-2023-40349 Vulnerability in maven package org.jenkins-ci.plugins:gogs-webhook
CVE-2023-41080 Vulnerability in maven package org.apache.tomcat:tomcat
CVE-2021-4103 Vulnerability in npm package vditor
CVE-2020-8910 Vulnerability in maven package org.webjars.npm:google-closure-library