CVE-2021-41615: Critical severity embedthis goahead web server vulnerability
websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparadise value, which does not follow the secret-data guideline for HTTP Digest Access Authentication in RFC 7616 section 3.3 (or RFC 2617 section 3.2.1). NOTE: 2.1.8 is a version from 2003; however, the affected websda.c code appears in multiple derivative works that may be used in 2021. Recent GoAhead software is unaffected.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-41615.
What is the severity of CVE-2021-41615?
The severity of CVE-2021-41615 is critical with a score of 9.8.
What is the affected software?
The affected software is GoAhead WebServer version 2.1.8.
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-331.
How can I fix this vulnerability?
To fix this vulnerability, update to a version of GoAhead WebServer that is not affected by this issue.