vendor:
Boa Web Server
by:
George Tsimpidas
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Boa Web Server
Affected Version From: 0.94.13
Affected Version To: 0.94.14
Patch Exists: YES
Related CWE:
CPE: a:boa:boa_web_server
Platforms Tested: Debian 5.18.5
2022
Boa Web Server v0.94.14 – Authentication Bypass
Boa Web Server Versions from 0.94.13 - 0.94.14 fail to validate the correct security constraint on the HEAD http method allowing everyone to bypass the Basic Authorization Mechanism.
Mitigation:
Ensure that the security constraints are properly validated for the HEAD http method.