First published: Mon May 18 2020(Updated: )
An arbitrary file download was found in the "Download Log" functionality of Wowza Streaming Engine <= 4.x.x. This issue was resolved in Wowza Streaming Engine 4.8.0.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wowza Streaming Engine | >=4.0.0<=4.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19454 is an arbitrary file download vulnerability found in the "Download Log" functionality of Wowza Streaming Engine.
The severity of CVE-2019-19454 is high, with a severity value of 7.5.
CVE-2019-19454 affects Wowza Streaming Engine versions <= 4.x.x.
To fix CVE-2019-19454, you need to upgrade to Wowza Streaming Engine 4.8.0 or later.
You can find more information about CVE-2019-19454 in the official release notes of Wowza Streaming Engine 4.8.0.