First published: Thu Nov 21 2024(Updated: )
Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an XML definition file anywhere on the file system.
Credit: cve@rapid7.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wowza Streaming Engine | <4.9.1 | |
All of | ||
Wowza Streaming Engine | >=4.3.0<4.9.1 | |
Any of | ||
Linux Kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52054 is classified as a critical vulnerability due to its potential to allow unauthorized file creation and access on the server.
To fix CVE-2024-52054, upgrade your Wowza Streaming Engine to version 4.9.1 or later.
CVE-2024-52054 allows an attacker to exploit path traversal to create XML definition files anywhere on the system, leading to potential unauthorized access.
Yes, CVE-2024-52054 can be exploited remotely if an attacker has administrator access to the vulnerable version of Wowza Streaming Engine.
CVE-2024-52054 affects all versions of Wowza Streaming Engine prior to 4.9.1.