com.netflix.hollow:hollow@6.1.0 vulnerabilities

  • latest version

    7.13.0

  • first published

    8 years ago

  • latest version published

    19 days ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the com.netflix.hollow:hollow package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Privilege Escalation

    Affected versions of this package are vulnerable to Privilege Escalation. In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure source of randomness is used, the file names to be created can be deterministically calculated.

    How to fix Privilege Escalation?

    There is no fixed version for com.netflix.hollow:hollow.

    [0,)