CVE-2021-43298: Critical severity embedthis goahead web server vulnerability
Published Jan 25, 2022
·Updated
The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This means that an unauthenticated network attacker can brute-force the HTTP basic password, byte-by-byte, by recording the webserver's response time until the unauthorized (401) response.
Affected Software
1 affected component
Embedthis GoAhead<5.1.4
Event History
Jan 25, 2022
CVE Published
via MITRE·07:11 PM
Data Sourced
via MITRE·07:11 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-43298.
2
What is the severity of CVE-2021-43298?
The severity of CVE-2021-43298 is critical with a CVSS score of 9.8.
3
Which software is affected by CVE-2021-43298?
Embedthis GoAhead version up to 5.1.4 is affected by CVE-2021-43298.
4
What is the impact of this vulnerability?
An unauthenticated network attacker can brute-force the HTTP basic password by recording the webserver's response time.
5
Is there a fix for CVE-2021-43298?
Yes, upgrading to a version beyond 5.1.4 of Embedthis GoAhead is recommended to fix CVE-2021-43298.