Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link.
References
Link | Resource |
---|---|
https://leostream.com/wp-content/uploads/2018/11/Leostream_release_notes.pdf | Release Notes Vendor Advisory |
https://www.leostream.com/resource/leostream-connection-broker-9-0/ | Release Notes Vendor Advisory |
Configurations
Information
Published : 2022-01-18 07:15
Updated : 2022-07-12 10:42
NVD link : CVE-2021-41551
Mitre link : CVE-2021-41551
JSON object : View
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
Products Affected
leostream
- connection_broker