CVE-2021-31540

CVE-2021-31540 - WOWZA Streaming Engine

Vulnerability Description: CWE-732: Incorrect Permission Assignment for Critical Resource
Software Version: < 4.8.5
NISThttps://nvd.nist.gov/vuln/detail/CVE-2021-31540
CVSv3: 7.1
Severity: High
Credits
: Francesco Giordano, Massimiliano Brolli

CVE-2021-31540

Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files in the conf/ directory. A regular local user is able to read and write to all the configuration files, e.g., modify the application server configuration.

Figure 1: File permissions

Click here to enlarge the image