Critical Netflix Genie Bug Opens Big Data Orchestration to RCE
ID: 7ec11e9a-1864-5b8f-b11b-31dbcea9d95f
STIX ID: report--7ec11e9a-1864-5b8f-b11b-31dbcea9d95f
Feed Name: Dark Reading
Threat Score
A critical path-traversal vulnerability (CVE-2024-4701, CVSS 9.9) in Netflix's Genie OSS allows attackers to manipulate uploaded filenames to write files outside the intended storage path, enabling remote code execution and potential exposure of credentials, application code, and big data sets; Netflix released a fix in Genie OSS 4.3.18 and researchers advise upgrading or restricting network access to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
