CVE-2021-33558
boa boa Exposure of Sensitive Information to an Unauthorized Actor
Record summary
CVE-2021-33558 has a selected CVSS score of 7.5 (high); EIP currently links 2 repository PoCs and 1 Nuclei template. VulnCheck reports CVE-2021-33558 use in known ransomware campaigns.
Description
Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE: multiple third parties report that this is a site-specific issue because those files are not part of Boa.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 14, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · VulnCheck
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 11, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
Proofs of concept
2Repository PoCs
GitHubmdanzaruddin/CVE-2021-33558.Repository PoCby mdanzaruddinStars: 3Not analyzed2 files
GitHubanldori/CVE-2021-33558Repository PoCby anldoriStars: 1Not analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHBoa 0.94.13 - Information DisclosureCVSS 7.5
Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE- multiple third parties report that this is a site-specific issue because those files are not part of Boa.
Impact
Unauthenticated attackers can access sensitive JavaScript files exposing logging functionality and potentially other configuration details.
Remediation
Update Boa web server to a version newer than 0.94.13 or apply vendor security patches.
Source: ProjectDiscovery