First published: Thu Nov 21 2024(Updated: )
Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any directory on the file system if the target directory contains an XML definition file.
Credit: cve@rapid7.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wowza Streaming Engine | <4.9.1 | |
All of | ||
Wowza Streaming Engine | >=4.3.0<4.9.1 | |
Any of | ||
Linux Kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52056 is considered a high severity vulnerability due to its potential to allow unauthorized directory deletions.
To fix CVE-2024-52056, upgrade Wowza Streaming Engine to version 4.9.1 or later.
CVE-2024-52056 affects Wowza Streaming Engine versions below 4.9.1.
CVE-2024-52056 enables path traversal attacks that can lead to unauthorized deletion of directories.
Yes, CVE-2024-52056 can potentially be exploited remotely by an administrator user.