
Cloud Vulnerability DB
A community-led vulnerabilities database
Boa Web Server versions 0.94.13 through 0.94.14 contain an authentication bypass vulnerability identified as CVE-2022-45956. The vulnerability was disclosed on December 12, 2022, and affects the web server's handling of the HEAD HTTP method. The issue specifically relates to the server's failure to properly validate security constraints on HEAD HTTP requests (NVD, CVE).
The vulnerability stems from a failure to validate the correct security constraint on the HEAD HTTP method, which allows attackers to bypass the Basic Authorization mechanism. The severity of this vulnerability has been assessed with a CVSS v3.1 Base Score of 5.3 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N. The vulnerability is classified under CWE-863 (Incorrect Authorization) (NVD).
The vulnerability allows unauthorized users to bypass the Basic Authorization mechanism, potentially gaining access to resources that should be protected. This could lead to unauthorized access to sensitive information or resources that were intended to be restricted (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."