Description
In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.
Remediation
References
https://github.com/quarkusio/quarkus/pull/30694
Related Vulnerabilities
CVE-2023-1428 Vulnerability in maven package io.grpc:grpc-protobuf
CVE-2017-16006 Vulnerability in maven package org.webjars.bower:remarkable
CVE-2020-35774 Vulnerability in maven package com.twitter:twitter-server
CVE-2021-23413 Vulnerability in npm package jszip
CVE-2023-36470 Vulnerability in maven package org.xwiki.platform:xwiki-platform-icon-script