PT-2022-27698 · Unknown · Boa Web Server

Published

2022-12-12

·

Updated

2025-04-22

·

CVE-2022-45956

CVSS v3.1
5.3
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Name of the Vulnerable Software and Affected Versions:

Boa Web Server versions 0.94.13 through 0.94.14

Description:

The issue allows bypassing of the Basic Authorization mechanism due to a failure in validating the correct security constraint on the HEAD HTTP method.

Recommendations:

For Boa Web Server versions 0.94.13 through 0.94.14, consider disabling the HEAD HTTP method until a patch is available to prevent bypassing of the Basic Authorization mechanism.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-45956

Affected Products

Boa Web Server