CVE-2020-9004: High severity Wowza Streaming Engine vulnerability
A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any read-only user to issue requests to the administration panel in order to change functionality. For example, a read-only user may activate the Java JMX port in unauthenticated mode and execute OS commands under root privileges. This issue was resolved in Wowza Streaming Engine 4.8.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wowza-streaming-engineto a version that resolves this vulnerability.Fixed in 4.8.5
Event History
Frequently Asked Questions
What is CVE-2020-9004?
CVE-2020-9004 is a remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.8.0 and earlier.
How does CVE-2020-9004 impact Wowza Streaming Engine?
CVE-2020-9004 allows any read-only user to issue requests to the administration panel and change functionality, potentially leading to unauthorized access and execution of arbitrary code.
What is the severity of CVE-2020-9004?
CVE-2020-9004 has a severity rating of 8.8, which is considered critical.
How can I fix CVE-2020-9004?
To fix CVE-2020-9004, users should update Wowza Streaming Engine to version 4.8.5 or later.
Where can I find more information about CVE-2020-9004?
More information about CVE-2020-9004 can be found in the references provided: [reference 1](https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2020-9004-Authenticated%20Remote%20Authorization%20Bypass%20Leading%20to%20RCE-Wowza), [reference 2](https://raw.githubusercontent.com/WowzaMediaSystems/public_cve/main/wowza-streaming-engine/CVE-2020-9004.txt), [reference 3](https://www.wowza.com/docs/wowza-streaming-engine-4-8-5-release-notes).