CVE-2026-41860
HIGH SEVERITYCVSS Score & Metrics
Base Score
8.8 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Description
CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an attacker to intercept traffic between bosh-monitor and the BOSH director or UAA and steal credentials.
Affected versions:
- BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later
Affected versions:
- BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-326
Source
NVD
Vendor
Cloud Foundry Foundation
Product
BOSH
Discussion (0)
Add Comment
No comments yet. Be the first!