PT-2021-17743 · Netflix · Netflix Oss Hollow
Jonathan Leitschuh
·
Published
2021-03-23
·
Updated
2023-08-08
·
CVE-2021-28099
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Netflix OSS Hollow (affected versions not specified)
Description:
The issue allows an attacker to pre-create directories with wide permissions since the
Files.exists(parent) check is performed before creating the directories. Furthermore, the use of an insecure source of randomness enables the deterministic calculation of file names to be created. This could allow an attacker to read or modify data written by the Hollow process if they can create directories and set permissions on the local filesystem.Recommendations:
Avoid running Hollow in configurations that share a filesystem with less-trusted processes.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netflix Oss Hollow