Cloud Foundry / BOSH
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-41861 | Arbitrary Root File Write via Path Traversal in BOSH agent | MEDIUM | 4.2 | Aug 6, 2026 |
| CVE-2026-41011 | PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['name'] comes… | HIGH | 8.7 | Jun 4, 2026 |
| CVE-2026-41859 | A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper… | HIGH | 7.1 | Jun 4, 2026 |
| CVE-2026-41860 | CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #s… | HIGH | 7.1 | Jun 4, 2026 |
| CVE-2026-41704 | Compromised VM can make arbitrary blobstore deletes | MEDIUM | 6.8 | May 27, 2026 |
| CVE-2026-41009 | Local Blobstore may allow arbitrary reads/deletes | MEDIUM | 4.3 | May 27, 2026 |
| CVE-2019-11271 | Bosh Deployment logs leak sensitive information | HIGH | 7.8 | Jun 18, 2019 |
| CVE-2018-11083 | Bosh accepts refresh tokens in place of an access token | HIGH | 8.1 | Oct 5, 2018 |
| CVE-2017-4961 | An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Direct… | HIGH | 8.8 | Jun 13, 2017 |
Showing 1 to 6 of 6 CVEs