CVE-2024-52054: Application Creation Path Traversal in Wowza Streaming Engine
Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an XML definition file anywhere on the file system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52054?
CVE-2024-52054 is classified as a critical vulnerability due to its potential to allow unauthorized file creation and access on the server.
How do I fix CVE-2024-52054?
To fix CVE-2024-52054, upgrade your Wowza Streaming Engine to version 4.9.1 or later.
What impact does CVE-2024-52054 have on my system?
CVE-2024-52054 allows an attacker to exploit path traversal to create XML definition files anywhere on the system, leading to potential unauthorized access.
Is CVE-2024-52054 exploitable remotely?
Yes, CVE-2024-52054 can be exploited remotely if an attacker has administrator access to the vulnerable version of Wowza Streaming Engine.
What versions of Wowza Streaming Engine are affected by CVE-2024-52054?
CVE-2024-52054 affects all versions of Wowza Streaming Engine prior to 4.9.1.