Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass the Basic Authorization mechanism.
2022-12-12T15:15:10.657
2025-04-22T20:15:26.207
Modified
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | boa | boa | 0.94.13 | Yes |
Application | boa | boa | 0.94.14 | Yes |