Directory Permission Vulnerability in Netflix OSS Hollow
CVE-2021-28099
4.4MEDIUM
What is CVE-2021-28099?
The vulnerability in Netflix OSS Hollow arises from the execution of 'Files.exists(parent)' before the creation of required directories. This flaw enables an attacker to pre-create directories with excessive permissions, thereby posing a significant risk. Furthermore, the use of an insecure source of randomness allows the attacker to predict the file names that will be generated, facilitating the exploitation of the vulnerability.
Affected Version(s)
Netflix OSS Hollow All versions