CVE-2023-0482: Medium severity ibm watson knowledge catalog vulnerability
Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-2c6g-pfx3-w7h8. This link is maintained to preserve external references.
Original Description In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
Other sources
Impact In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
Patches Fixed in the following pull requests:
https://github.com/resteasy/resteasy/pull/3409 (7.0.0.Alpha1) https://github.com/resteasy/resteasy/pull/3423 (6.2.3.Final) https://github.com/resteasy/resteasy/pull/3412 (5.0.6.Final) https://github.com/resteasy/resteasy/pull/3413 (4.7.8.Final) https://github.com/resteasy/resteasy/pull/3410 (3.15.5.Final)
Workarounds There is no workaround for this issue.
References https://nvd.nist.gov/vuln/detail/CVE-2023-0482 https://bugzilla.redhat.com/showbug.cgi?id=2166004 https://github.com/advisories/GHSA-jrmh-v64j-mjm9
— GitHub
RESTEasy could allow a local authenticated attacker to gain elevated privileges on the system, caused by the creation of insecure temp files in the File.createTempFile() used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges.
— IBM
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-0482.
What is the severity of CVE-2023-0482?
The severity of CVE-2023-0482 is medium, with a severity value of 5.3.
Which software is affected by CVE-2023-0482?
RESTEasy, eap7-resteasy, rh-sso7-keycloak, Redhat Resteasy, and IBM Watson Knowledge Catalog on-prem are affected by CVE-2023-0482.
How can a local authenticated attacker exploit CVE-2023-0482?
A local authenticated attacker can exploit CVE-2023-0482 by sending a specially-crafted request.
Are there any patches or fixes available for CVE-2023-0482?
Yes, patches or fixes are available. Please refer to the following references for more information: [link1](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2170572), [link2](https://access.redhat.com/errata/RHSA-2023:1514), [link3](https://access.redhat.com/errata/RHSA-2023:1513).