CVE-2021-28099

In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure source of randomness is used, the file names to be created can be deterministically calculated.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:netflix:hollow:-:*:*:*:*:*:*:*

Information

Published : 2021-03-23 14:15

Updated : 2021-03-26 13:16


NVD link : CVE-2021-28099

Mitre link : CVE-2021-28099


JSON object : View

Advertisement

dedicated server usa

Products Affected

netflix

  • hollow