CVE-2022-45956

MEDIUM

Boa 0.94.13-0.94.14 - Authentication Bypass via HEAD HTTP Method

Title source: llm
STIX 2.1

Description

Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0082
EPSS Percentile 52.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (2)
boa/boa 0.94.13
boa/boa 0.94.14
Published Dec 12, 2022
Tracked Since Feb 18, 2026