An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on the Director VM, aka "BOSH Director Shell Injection Vulnerabilities."
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "260"
},
{
"introduced": "0"
},
{
"last_affected": "260.1"
},
{
"introduced": "0"
},
{
"last_affected": "260.2"
},
{
"introduced": "0"
},
{
"last_affected": "260.3"
},
{
"introduced": "0"
},
{
"last_affected": "260.4"
},
{
"introduced": "0"
},
{
"last_affected": "260.5"
},
{
"introduced": "0"
},
{
"last_affected": "260.6"
},
{
"introduced": "0"
},
{
"last_affected": "261"
},
{
"introduced": "0"
},
{
"last_affected": "261.1"
},
{
"introduced": "0"
},
{
"last_affected": "261.2"
}
]
}