Authentication Bypass Vulnerability in Boa Web Server by Boa Developer
CVE-2022-45956
5.3MEDIUM
What is CVE-2022-45956?
The Boa Web Server versions 0.94.13 and 0.94.14 are vulnerable due to inadequate validation of the security constraints for the HEAD HTTP method. This flaw allows unauthorized users to bypass the Basic Authorization control, potentially compromising the security of the server and exposing sensitive resources to unintended access. It is crucial for users operating these versions to assess their security posture and consider applying the necessary updates to mitigate this risk.