ZeroHour

CVE-2021-28099

CVSS 3.1
4.4 medium
EPSS
<1%p15
Published
()
Modified
Description

In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure source of randomness is used, the file names to be created can be deterministically calculated.

Vendors
netflix
Products
hollow
Weakness
CWE-330
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.