CVE-2021-28099

MEDIUM

Netflix OSS Hollow - Info Disclosure

Title source: llm
STIX 2.1

Description

In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure source of randomness is used, the file names to be created can be deterministically calculated.

References (1)

Core 1

Scores

CVSS v3 4.4
EPSS 0.0024
EPSS Percentile 15.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-330
Status published
Products (2)
com.netflix.hollow/hollow 0Maven
netflix/hollow
Published Mar 23, 2021
Tracked Since Feb 18, 2026