In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
Loading...
Loading...
This medium-severity CVE scores 5.5 under NVD CVSS v3. EPSS exploit probability: 0.1%, top 84% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
February 17, 2023
March 18, 2025
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | libresteasy-java (3.6.2-2ubuntu0.22.04.1~esm1) @ jammy | 2026-05-25 | ubuntu |
| ubuntu | libresteasy3.0-java (3.0.26-1~18.04.1~esm1) @ bionic | 2026-05-25 | ubuntu |
| redhat | RESTEasy | 2024-03-18 | redhat |
| redhat | mta/mta-windup-addon-rhel8:6.1.4-2 | 2023-11-06 | redhat |
| redhat | patch | 2023-09-14 | redhat |
| redhat | rh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el8sso | 2023-05-10 | redhat |
| redhat | rh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el7sso | 2023-05-10 | redhat |
| redhat | rh-sso7-keycloak-0:18.0.7-1.redhat_00001.1.el9sso | 2023-05-10 | redhat |
| redhat | rh-sso-7/sso76-openshift-rhel8:7.6-22 | 2023-05-10 | redhat |
| redhat | eap7-resteasy-0:3.15.5-1.Final_redhat_00001.1.el8eap | 2023-03-29 | redhat |
| redhat | eap7-resteasy-0:3.15.5-1.Final_redhat_00001.1.el9eap | 2023-03-29 | redhat |
| redhat | eap7-resteasy-0:3.15.5-1.Final_redhat_00001.1.el7eap | 2023-03-29 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.jboss.resteasy:resteasy-core | — | 3.15.5.Final | — |
| org.jboss.resteasy:resteasy-multipart-provider | 1.0-RC1 ... 3.9.3.SP1 (125 versions) | 3.15.5.Final | — |
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
RHSA-2023:1512 — Low
RHSA-2023:1513 — Low
RHSA-2023:1514 — Low
RHSA-2023:1516 — Low
RHSA-2023:2705 — Low
RHSA-2023:2706 — Low
RHSA-2023:2707 — Low
RHSA-2023:2710 — Low
RHSA-2023:2713 — Low
RHSA-2023:3185 — Low
RHSA-2023:4983 — Low
RHSA-2023:5165 — Low
RHSA-2024:1353 — Low
RESTEasy vulnerabilities
RESTEasy vulnerabilities
See which npm, PyPI, Go, and Maven packages are affected by CVE-2023-0482
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.