CVE-2022-45956: Medium severity boa boa vulnerability
Published Dec 12, 2022
·Updated
Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.
Affected Software
2 affected components
Boa Boa=0.94.13
Boa Boa=0.94.14
Event History
Dec 12, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-45956?
CVE-2022-45956 is considered a critical vulnerability due to the authentication bypass it allows.
2
How do I fix CVE-2022-45956?
To fix CVE-2022-45956, you should upgrade to a later version of the Boa Web Server beyond 0.94.14.
3
What versions are affected by CVE-2022-45956?
CVE-2022-45956 affects Boa Web Server versions 0.94.13 and 0.94.14.
4
What type of vulnerability is CVE-2022-45956?
CVE-2022-45956 is classified as an authentication bypass vulnerability.
5
Can CVE-2022-45956 be exploited remotely?
Yes, CVE-2022-45956 can be exploited remotely, allowing unauthorized access to protected resources.