Directory Permission Vulnerability in Netflix OSS Hollow
CVE-2021-28099

4.4MEDIUM

Key Information:

Vendor

Netflix

Vendor
CVE Published:
23 March 2021

What is CVE-2021-28099?

The vulnerability in Netflix OSS Hollow arises from the execution of 'Files.exists(parent)' before the creation of required directories. This flaw enables an attacker to pre-create directories with excessive permissions, thereby posing a significant risk. Furthermore, the use of an insecure source of randomness allows the attacker to predict the file names that will be generated, facilitating the exploitation of the vulnerability.

Affected Version(s)

Netflix OSS Hollow All versions

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.