PT-2021-17743 · Netflix · Netflix Oss Hollow

Jonathan Leitschuh

·

Published

2021-03-23

·

Updated

2023-08-08

·

CVE-2021-28099

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Netflix OSS Hollow (affected versions not specified)
Description: The issue allows an attacker to pre-create directories with wide permissions since the Files.exists(parent) check is performed before creating the directories. Furthermore, the use of an insecure source of randomness enables the deterministic calculation of file names to be created. This could allow an attacker to read or modify data written by the Hollow process if they can create directories and set permissions on the local filesystem.
Recommendations: Avoid running Hollow in configurations that share a filesystem with less-trusted processes. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

CVE-2021-28099
GHSA-9295-MHF3-V33M

Affected Products

Netflix Oss Hollow