CVE-2021-33558: High severity boa boa vulnerability
DISPUTED Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE: multiple third parties report that this is a site-specific issue because those files are not part of Boa.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33558?
CVE-2021-33558 is marked as a moderate severity vulnerability due to the risk of sensitive information exposure.
How do I fix CVE-2021-33558?
To fix CVE-2021-33558, ensure proper configuration settings and restrict access to sensitive files like backup.html and config.js.
Who is affected by CVE-2021-33558?
CVE-2021-33558 affects instances of Boa web server version 0.94.13 that are misconfigured.
What type of vulnerability is CVE-2021-33558?
CVE-2021-33558 is a type of information disclosure vulnerability.
Can CVE-2021-33558 be exploited remotely?
Yes, CVE-2021-33558 can be exploited by remote attackers to obtain sensitive information.