Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-28099

In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure source of randomness is used, the file names to be created can be deterministically calculated.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 8.4%
CVSS Severity
CVSS v3 Score 4.4
CVSS v2 Score 3.6
Products affected by CVE-2021-28099


Contact Us

Shodan ® - All rights reserved