CVE-2026-47829
- EPSS 0.23%
- Veröffentlicht 09.07.2026 06:25:56
- Zuletzt bearbeitet 13.07.2026 13:33:49
Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command e...
CVE-2026-47828
- EPSS 0.15%
- Veröffentlicht 09.07.2026 06:07:10
- Zuletzt bearbeitet 13.07.2026 13:35:57
During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoint is availabl...
CVE-2026-47826
- EPSS 0.34%
- Veröffentlicht 09.07.2026 05:45:33
- Zuletzt bearbeitet 13.07.2026 13:36:53
The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.
CVE-2026-41857
- EPSS 0.15%
- Veröffentlicht 09.07.2026 04:31:33
- Zuletzt bearbeitet 13.07.2026 13:37:39
A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versions prior to 7.10.5.