
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A critical remote code execution (RCE) vulnerability has been discovered in Genie, Netflix's open-source job orchestration engine for big data processing. The vulnerability, identified as CVE-2024-4701 with a CVSS score of 9.9, was discovered and reported by security researchers. Genie, developed by Netflix, is used extensively to manage big data jobs across multiple distributed processing clusters and supports various platforms like Hadoop, Pig, Hive, Spark, Presto, and Sqoop (Dark Reading, Security Online).
The vulnerability exists in Genie's API that handles file uploads, where it accepts a user-supplied filename as part of the multipart/form-data request. The flaw allows attackers to manipulate the filename parameter to perform path traversal attacks, enabling them to write files outside of the intended storage path. This technique allows writing files with arbitrary content to any location where the Java process has write permissions. The issue affects all versions of Genie OSS prior to 4.3.18 (Netflix Advisory).
Successful exploitation of CVE-2024-4701 could allow attackers to execute arbitrary code on vulnerable Genie servers, potentially leading to complete system compromise. The vulnerability could expose sensitive information including credentials for back-end systems, application code and data, and sensitive operating system files. The impact is particularly severe for organizations running their own Genie OSS instances that store file attachments locally on the underlying file system (Dark Reading).
Netflix has addressed this vulnerability in Genie OSS version 4.3.18. Organizations are strongly advised to upgrade to this patched version immediately. For those unable to update immediately, it is recommended to limit network access to the Genie application and ensure it is not accessible from the Internet (Netflix Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”