CVE-2023-0482: Medium severity ibm watson knowledge catalog vulnerability

Published Jan 31, 2023
·
Updated

Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-2c6g-pfx3-w7h8. This link is maintained to preserve external references.

Original Description In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.

Other sources

Impact In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.

Patches Fixed in the following pull requests:

https://github.com/resteasy/resteasy/pull/3409 (7.0.0.Alpha1) https://github.com/resteasy/resteasy/pull/3423 (6.2.3.Final) https://github.com/resteasy/resteasy/pull/3412 (5.0.6.Final) https://github.com/resteasy/resteasy/pull/3413 (4.7.8.Final) https://github.com/resteasy/resteasy/pull/3410 (3.15.5.Final)

Workarounds There is no workaround for this issue.

References https://nvd.nist.gov/vuln/detail/CVE-2023-0482 https://bugzilla.redhat.com/showbug.cgi?id=2166004 https://github.com/advisories/GHSA-jrmh-v64j-mjm9

GitHub

RESTEasy could allow a local authenticated attacker to gain elevated privileges on the system, caused by the creation of insecure temp files in the File.createTempFile() used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges.

IBM

Affected Software

29 affected componentsFixes available
redhat/eap7-resteasy<0:3.15.5-1.Final_redhat_00001.1.el8ea
0:3.15.5-1.Final_redhat_00001.1.el8ea
redhat/eap7-resteasy<0:3.15.5-1.Final_redhat_00001.1.el9ea
0:3.15.5-1.Final_redhat_00001.1.el9ea
redhat/eap7-resteasy<0:3.15.5-1.Final_redhat_00001.1.el7ea
0:3.15.5-1.Final_redhat_00001.1.el7ea
redhat/rh-sso7-keycloak<0:18.0.7-1.redhat_00001.1.el7
0:18.0.7-1.redhat_00001.1.el7
redhat/rh-sso7-keycloak<0:18.0.7-1.redhat_00001.1.el8
0:18.0.7-1.redhat_00001.1.el8
redhat/rh-sso7-keycloak<0:18.0.7-1.redhat_00001.1.el9
0:18.0.7-1.redhat_00001.1.el9
redhat/RESTEasy<4.7.8.
4.7.8.
maven/org.jboss.resteasy:resteasy-core<3.15.4.Final
3.15.5.Final
maven/org.jboss.resteasy:resteasy-multipart-provider<3.15.4.Final
3.15.5.Final
maven/org.jboss.resteasy:resteasy-multipart-provider>=4.0.0.Beta1<4.7.8.Final
4.7.8.Final
maven/org.jboss.resteasy:resteasy-multipart-provider>=5.0.0.Alpha1<5.0.6.Final
5.0.6.Final
maven/org.jboss.resteasy:resteasy-multipart-provider>=6.0.0.Beta1<6.2.3.Final
6.2.3.Final
maven/org.jboss.resteasy:resteasy-core>=4.0.0.Beta1<4.7.8.Final
4.7.8.Final
maven/org.jboss.resteasy:resteasy-core>=5.0.0.Alpha1<5.0.6.Final
5.0.6.Final
maven/org.jboss.resteasy:resteasy-core>=6.0.0.Beta1<6.2.3.Final
6.2.3.Final
maven/org.jboss.resteasy:resteasy-multipart-provider<4.7.8.Final
4.7.8.Final
maven/org.jboss.resteasy:resteasy-core<4.7.8.Final
4.7.8.Final
IBM Watson Knowledge Catalog on-prem<=4.x
redhat resteasy<4.7.8
debian/resteasy<=3.6.2-3
debian/resteasy3.0<=3.0.26-2, <=3.0.26-6
redhat resteasy=3.15.4
redhat resteasy=4.7.7
redhat resteasy=5.0.5
redhat resteasy=6.2.2
NetApp Active Iq Unified Manager Linux
NetApp Active Iq Unified Manager Vsphere
NetApp Active Iq Unified Manager Windows
NetApp OnCommand Workflow Automation

Event History

Jan 31, 2023
CVE Published
12:00 AM
Data Sourced
via Red Hat·04:47 PM
DescriptionSeverityAffected Software
Feb 17, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 18, 2023
Advisory Published
via GitHub·12:31 AM
Jan 15, 2025
Withdrawn
via GitHub·06:56 PM
Mar 13, 2025
Data Sourced
via Ubuntu·02:41 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·02:42 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the vulnerability ID?

The vulnerability ID is CVE-2023-0482.

2

What is the severity of CVE-2023-0482?

The severity of CVE-2023-0482 is medium, with a severity value of 5.3.

3

Which software is affected by CVE-2023-0482?

RESTEasy, eap7-resteasy, rh-sso7-keycloak, Redhat Resteasy, and IBM Watson Knowledge Catalog on-prem are affected by CVE-2023-0482.

4

How can a local authenticated attacker exploit CVE-2023-0482?

A local authenticated attacker can exploit CVE-2023-0482 by sending a specially-crafted request.

5

Are there any patches or fixes available for CVE-2023-0482?

Yes, patches or fixes are available. Please refer to the following references for more information: [link1](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2170572), [link2](https://access.redhat.com/errata/RHSA-2023:1514), [link3](https://access.redhat.com/errata/RHSA-2023:1513).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203