First published: Thu May 27 2021(Updated: )
** DISPUTED ** Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE: multiple third parties report that this is a site-specific issue because those files are not part of Boa.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Boa Boa | =0.94.13 | |
=0.94.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33558 is marked as a moderate severity vulnerability due to the risk of sensitive information exposure.
To fix CVE-2021-33558, ensure proper configuration settings and restrict access to sensitive files like backup.html and config.js.
CVE-2021-33558 affects instances of Boa web server version 0.94.13 that are misconfigured.
CVE-2021-33558 is a type of information disclosure vulnerability.
Yes, CVE-2021-33558 can be exploited by remote attackers to obtain sensitive information.