Description
In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.
Remediation
References
https://github.com/quarkusio/quarkus/pull/30694
Related Vulnerabilities
CVE-2023-26048 Vulnerability in maven package org.eclipse.jetty:jetty-server
CVE-2023-29528 Vulnerability in maven package org.xwiki.commons:xwiki-commons-xml
CVE-2020-6428 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-35931 Vulnerability in npm package shescape
CVE-2014-7810 Vulnerability in maven package org.apache.tomcat:jasper