CVE-2024-52055

Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any file on the file system if the target directory contains an XML definition file.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:wowza:streaming_engine:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

17 Jun 2026, 08:06

Type Values Removed Values Added
References () https://www.rapid7.com/blog/post/2024/11/20/multiple-vulnerabilities-in-wowza-streaming-engine-fixed/ - () https://www.rapid7.com/blog/post/2024/11/20/multiple-vulnerabilities-in-wowza-streaming-engine-fixed/ - Third Party Advisory
References () https://www.wowza.com/docs/wowza-streaming-engine-4-9-1-release-notes - () https://www.wowza.com/docs/wowza-streaming-engine-4-9-1-release-notes - Release Notes
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:wowza:streaming_engine:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.9
Summary
  • (es) El Path Traversal en el componente Administrador de Wowza Streaming Engine anterior a 4.9.1 permite que un usuario administrador lea cualquier archivo en el sistema de archivos si el directorio de destino contiene un archivo de definición XML.
First Time Linux linux Kernel
Microsoft windows
Wowza streaming Engine
Wowza
Linux
Microsoft

21 Nov 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-21 23:15

Updated : 2026-06-17 08:06


NVD link : CVE-2024-52055

Mitre link : CVE-2024-52055

CVE.ORG link : CVE-2024-52055


JSON object : View

Products Affected

microsoft

  • windows

wowza

  • streaming_engine

linux

  • linux_kernel
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')