ZeroHour

CVE-2022-45956

PoC
CVSS 3.1
5.3 medium
EPSS
<1%p55
Published
()
Modified
Description

Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.

Vendors
boa
Products
boa
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.