logo

Critical Netflix Genie Bug Opens Big Data Orchestration to RCE

ID: 7ec11e9a-1864-5b8f-b11b-31dbcea9d95f

STIX ID: report--7ec11e9a-1864-5b8f-b11b-31dbcea9d95f

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-05-22

Date Updated: 2026-05-05

Author: Jai Vijayan, Contributing Writer

...
...

A critical path-traversal vulnerability (CVE-2024-4701, CVSS 9.9) in Netflix's Genie OSS allows attackers to manipulate uploaded filenames to write files outside the intended storage path, enabling remote code execution and potential exposure of credentials, application code, and big data sets; Netflix released a fix in Genie OSS 4.3.18 and researchers advise upgrading or restricting network access to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.