VYPR

BOSH Release

by Cloudfoundry

CVEs (3)

  • CVE-2017-4961HigJun 13, 2017
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on the Director VM, aka…

  • CVE-2017-4972HigJun 13, 2017
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prior to v3.15.0; and UAA bosh release (uaa-release) 13.x…

  • CVE-2026-47833Jun 18, 2026
    risk 0.00cvss epss

    setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A compromised process inside a bpm container can cause root to chown an arbitrary host file to vcap and append bpm JSON log lines to it. The chown alone lets the…