CVE-2021-28099

Published
View on NVD ↗
CVSS v3
4.4
MEDIUM
CVSS v2
3.6
LOW
Affected
1
PROJECT

Description

In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure source of randomness is used, the file names to be created can be deterministically calculated.

Security Bulletins that relate to Netflix Open Source
GitHubGitHub
746