CVE-2021-28099
23.03.2021, 21:15
In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure source of randomness is used, the file names to be created can be deterministically calculated.Enginsight
Vendor | Product | Version |
---|---|---|
netflix | hollow | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration