CVE-2021-41764
Estado: ModificadaAlta (8.8)—
A cross-site request forgery (CSRF) vulnerability exists in Streama up to and including v1.10.3. The application does not have CSRF checks in place when performing actions such as uploading local files. As a result, attackers could make a logged-in administrator upload arbitrary local files via a CSRF attack and send them to the attacker.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.71%
- Percentil entre todas las CVEs puntuadas: 52
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-352
Referencias
- https://gist.github.com/omriinbar/3c741d309e5d0ede29dc7ecdad4eba3f
- https://gist.github.com/omriinbar/8277193731d0edf20ef71299f304ab93
- https://github.com/streamaserver/streama
- https://gist.github.com/omriinbar/3c741d309e5d0ede29dc7ecdad4eba3f
- https://gist.github.com/omriinbar/8277193731d0edf20ef71299f304ab93
- https://github.com/streamaserver/streama
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-41764",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2021-09-29T20:15:08.703",
"references": [
{
"url": "https://gist.github.com/omriinbar/3c741d309e5d0ede29dc7ecdad4eba3f",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://gist.github.com/omriinbar/8277193731d0edf20ef71299f304ab93",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/streamaserver/streama",
"tags": [
"Product",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://gist.github.com/omriinbar/3c741d309e5d0ede29dc7ecdad4eba3f",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://gist.github.com/omriinbar/8277193731d0edf20ef71299f304ab93",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/streamaserver/streama",
"tags": [
"Product",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A cross-site request forgery (CSRF) vulnerability exists in Streama up to and including v1.10.3. The application does not have CSRF checks in place when performing actions such as uploading local files. As a result, attackers could make a logged-in administrator upload arbitrary local files via a CSRF attack and send them to the attacker."
},
{
"lang": "es",
"value": "Se presenta una vulnerabilidad de tipo cross-site request forgery (CSRF) en Streama versiones hasta v1.10.3 incluyéndola. La aplicación no dispone de comprobaciones CSRF cuando lleva a cabo acciones como la carga de archivos locales. Como resultado, los atacantes podrían hacer que un administrador conectado cargue archivos locales arbitrarios por medio de un ataque de tipo CSRF y los envíe al atacante"
}
],
"lastModified": "2026-06-17T04:08:52.880",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:streama_project:streama:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF897CC6-4812-4350-BF38-1B93D421421A",
"versionEndIncluding": "1.10.3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}