Описание
Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:boa:boa:0.94.13:*:*:*:*:*:*:*
cpe:2.3:a:boa:boa:0.94.14:*:*:*:*:*:*:*
EPSS
Процентиль: 54%
0.00815
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-863
CWE-863
Связанные уязвимости
CVSS3: 5.3
ubuntu
больше 3 лет назад
Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.
CVSS3: 5.3
debian
больше 3 лет назад
Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the c ...
CVSS3: 5.3
github
больше 3 лет назад
Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.
EPSS
Процентиль: 54%
0.00815
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-863
CWE-863