VYPR

Bosh CLI

by Cloudfoundry

Source repositories

CVEs (5)

  • CVE-2018-1231HigMar 27, 2018
    risk 0.57cvss 8.8epss 0.01

    Cloud Foundry BOSH CLI, versions prior to v3.0.1, contains an improper access control vulnerability. A user with access to an instance using the BOSH CLI can access the BOSH CLI configuration file and use its contents to perform authenticated requests to BOSH.

  • CVE-2026-47829HigJul 9, 2026
    risk 0.00cvss 7.8epss 0.00

    Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's…

  • CVE-2026-47828HigJul 9, 2026
    risk 0.00cvss 8.8epss 0.00

    During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoint is available in the installation…

  • CVE-2026-47826CriJul 9, 2026
    risk 0.00cvss 9.1epss 0.00

    The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

  • CVE-2026-41857HigJul 9, 2026
    risk 0.00cvss 7.8epss 0.00

    A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versions prior to 7.10.5.