Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9g39-jgf9-9mxx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.7.8 (build 20191105123929) allows any read-only user to issue requests to the administration panel in order to change functionality. For example, a read-only user may activate the Java JMX port in unauthenticated mode and execute OS commands under root privileges.

A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.7.8 (build 20191105123929) allows any read-only user to issue requests to the administration panel in order to change functionality. For example, a read-only user may activate the Java JMX port in unauthenticated mode and execute OS commands under root privileges.

EPSS

Процентиль: 67%
0.00538
Низкий

8.8 High

CVSS3

Дефекты

CWE-306
CWE-863

Связанные уязвимости

CVSS3: 8.8
nvd
почти 6 лет назад

A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any read-only user to issue requests to the administration panel in order to change functionality. For example, a read-only user may activate the Java JMX port in unauthenticated mode and execute OS commands under root privileges. This issue was resolved in Wowza Streaming Engine 4.8.5.

EPSS

Процентиль: 67%
0.00538
Низкий

8.8 High

CVSS3

Дефекты

CWE-306
CWE-863