Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link.
References
Link | Resource |
---|---|
https://leostream.com/wp-content/uploads/2018/11/Leostream_release_notes.pdf | Release Notes Vendor Advisory |
https://www.leostream.com/resource/leostream-connection-broker-9-0/ | Release Notes Vendor Advisory |
https://leostream.com/wp-content/uploads/2018/11/Leostream_release_notes.pdf | Release Notes Vendor Advisory |
https://www.leostream.com/resource/leostream-connection-broker-9-0/ | Release Notes Vendor Advisory |
Configurations
History
21 Nov 2024, 06:26
Type | Values Removed | Values Added |
---|---|---|
References | () https://leostream.com/wp-content/uploads/2018/11/Leostream_release_notes.pdf - Release Notes, Vendor Advisory | |
References | () https://www.leostream.com/resource/leostream-connection-broker-9-0/ - Release Notes, Vendor Advisory |
Information
Published : 2022-01-18 15:15
Updated : 2024-11-21 06:26
NVD link : CVE-2021-41551
Mitre link : CVE-2021-41551
CVE.ORG link : CVE-2021-41551
JSON object : View
Products Affected
leostream
- connection_broker
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')