Privilege Escalation Affecting package, versions [0,]

  published

    25 Mar 2021

  disclosed

    24 Mar 2021

  credit

    Jonathan Leitschuh

How to fix?

There is no fixed version for


Affected versions of this package are vulnerable to Privilege Escalation. In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure source of randomness is used, the file names to be created can be deterministically calculated.