Description
In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.
Remediation
References
https://github.com/quarkusio/quarkus/pull/30694
Related Vulnerabilities
CVE-2021-35513 Vulnerability in maven package org.webjars.bower:mermaid
CVE-2021-43090 Vulnerability in maven package com.predic8:soa-model-parent
CVE-2023-35157 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2014-0050 Vulnerability in maven package org.apache.jackrabbit:oak-run
CVE-2022-23540 Vulnerability in maven package org.webjars.npm:jsonwebtoken