id: CVE-2021-33558 info: name: Boa 0.94.13 - Information Disclosure author: DhiyaneshDK severity: high description: | Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, email.html, online-users.html, and config.js. NOTE- multiple third parties report that this is a site-specific issue because those files are not part of Boa. impact: | Unauthenticated attackers can access sensitive JavaScript files exposing logging functionality and potentially other configuration details. remediation: | Update Boa web server to a version newer than 0.94.13 or apply vendor security patches. reference: - https://sourceforge.net/projects/boa/files/boa/0.94.13/ - https://github.com/anldori/CVE-2021-33558 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2021-33558 epss-score: 0.82894 epss-percentile: 0.99273 cpe: cpe:2.3:a:boa:boa:0.94.13:*:*:*:*:*:*:* metadata: max-request: 1 vendor: boa product: boa shodan-query: 'Server: Boa/0.94.13' fofa-query: "Server: Boa/0.94.13" tags: cve,cve2021,boa,info-leak,vkev,vuln http: - method: GET path: - "{{BaseURL}}/js/log.js" matchers-condition: and matchers: - type: word part: body words: - "function SearchLog" - "logTime" condition: and case-insensitive: true - type: status status: - 200 # digest: 4b0a00483046022100e3ec75878868a393167e7600c27b27aa023d92f18c3de76a914eb08fbb9cb5fc022100a6984325fbdd379b2c00c8d83d40c763f4c2bc00042c6895785dd07260931b9e:922c64590222798bb761d5b6d8e72950