Back to Labs
Security Advisory

CVE-2022-44117

About

Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa does not ship with any support for SQL.

Weakness (CWE):CWE-89

Rainforest analyst review

This entry claims a 9.8 unauthenticated SQL injection in Boa 0.94.14rc21 via the username field, but it is disputed by multiple third parties on a fundamental basis: Boa is a lightweight web server that ships with no SQL support at all. If there is no database layer, there is no SQL to inject, which is why the dispute exists and why the CRITICAL rating should be read with heavy skepticism.

Disputed CVEs with an implausible technical premise are noise that inflates queues if taken at face value. There is no credible mass-exploitation story for a SQL injection in a component that has no SQL, and treating this as a live 9.8 would divert effort from real issues. Boa does appear in embedded devices, so the product name is worth recognizing, but this specific claim isn't the reason to worry about it.

Our recommendation is to rank this down aggressively and flag it as disputed rather than actioning it as critical. If Boa is present in our embedded fleet, the productive move is to look at Boa's actual, well-documented vulnerability history and its exposure, not to chase a SQL-injection claim against a server that doesn't do SQL.

References

Related CVEs

Frequently asked questions

What is CVE-2022-44117?

Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa does not ship with any support for SQL.

How severe is CVE-2022-44117?

CVE-2022-44117 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.

How is CVE-2022-44117 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2022-44117?

Public advisories list the following as affected: boa. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2022-44117?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email