CVE-2021-28099

Severity CVSS v4.0:
Pending analysis
Type:
CWE-330 Use of Insufficiently Random Value
Publication date:
23/03/2021
Last modified:
08/08/2023

Description

In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure source of randomness is used, the file names to be created can be deterministically calculated.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netflix:hollow:-:*:*:*:*:*:*:*