Skip to main content

Vendor/product archive

cloud_foundry / bosh CVEs

Beta · best-effort

5 CVEs tagged to cloud_foundry / bosh0 Critical, 3 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-41704

Published May 27, 2026

AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every response, which reads response['value']['result']['compile_lo…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41009

Published May 27, 2026

When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient. inject_compile_log (line 332-339) reads response['value']…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-11271

Published Jun 19, 2019

Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticat…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11083

Published Oct 5, 2018

Cloud Foundry BOSH, versions v264 prior to v264.14.0 and v265 prior to v265.7.0 and v266 prior to v266.8.0 and v267 prior to v267.2.0, allows refresh tokens to be as access tokens…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4961

Published Jun 13, 2017

An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1