First published: Mon Dec 12 2022(Updated: )
Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Boa Boa | =0.94.13 | |
Boa Boa | =0.94.14 | |
=0.94.13 | ||
=0.94.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45956 is considered a critical vulnerability due to the authentication bypass it allows.
To fix CVE-2022-45956, you should upgrade to a later version of the Boa Web Server beyond 0.94.14.
CVE-2022-45956 affects Boa Web Server versions 0.94.13 and 0.94.14.
CVE-2022-45956 is classified as an authentication bypass vulnerability.
Yes, CVE-2022-45956 can be exploited remotely, allowing unauthorized access to protected resources.