Cloudfoundry

Bosh Cli

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 09.07.2026 06:25:56
  • Zuletzt bearbeitet 13.07.2026 13:33:49

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command e...

  • EPSS 0.15%
  • Veröffentlicht 09.07.2026 06:07:10
  • Zuletzt bearbeitet 13.07.2026 13:35:57

During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoint is availabl...

  • EPSS 0.34%
  • Veröffentlicht 09.07.2026 05:45:33
  • Zuletzt bearbeitet 13.07.2026 13:36:53

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

  • EPSS 0.15%
  • Veröffentlicht 09.07.2026 04:31:33
  • Zuletzt bearbeitet 13.07.2026 13:37:39

A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versions prior to 7.10.5.