"Critical Netflix Genie Bug Opens Big Data Orchestration to RCE"
"Critical Netflix Genie Bug Opens Big Data Orchestration to RCE"
A critical vulnerability in the open source version of Netflix's Genie job orchestration engine enables remote attackers to execute arbitrary code on systems running affected versions of the software. The bug has a near-max critical score of 9.9 out of 10 on the CVSS vulnerability severity scale. It attacks organizations that run their own Genie OSS instance, uploading and storing user-submitted file attachments via the underlying local file system.