Showing 3 vulnerabilities on this page for boa

Signals CISA KEV Ransomware Nuclei
boa vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objects

Boa is an embeddable and experimental Javascript engine written in Rust. Starting in version 0.16 and prior to version 0.19.0, a wrong assumption made when handling ECMAScript's `AsyncGenerator` operations can cause an uncaught exception on certain scripts. Boa's implementation of `AsyncGenerator` makes the assumption that the state of an `AsyncGenerator` object cannot change while resolving a promise created by methods of `AsyncGenerator` such as `%AsyncGeneratorPrototype%.next`, `%AsyncGenerat

CWE-248Aug 15, 2024
CVSS7.5v3.1EPSS0.597%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

boa boa Exposure of Sensitive Information to an Unauthorized Actor

Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE: multiple third parties report that this is a site-specific issue because those files are not part of Boa.

CWE-200May 27, 20211 related artifact
CVSS7.5v3.1EPSS12.3%PoCs2SignalsNot listed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

boa boa Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on one type of camera) because Boa does not include any wapopen program or any code to read a FILECAMERA variable.

CWE-22Jun 24, 20171 related artifact
CVSS7.5v3.1EPSS68.5%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX