An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on the Director VM, aka "BOSH Director Shell Injection Vulnerabilities."
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:cloud_foundry:bosh:260.7:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "cloud_foundry:bosh",
"extracted_events": [
{
"introduced": "260.7"
},
{
"last_affected": "260.7"
}
]
}
]
}{
"cpe": [
"cpe:2.3:a:cloud_foundry:bosh:260:*:*:*:*:*:*:*",
"cpe:2.3:a:cloud_foundry:bosh:260.1:*:*:*:*:*:*:*",
"cpe:2.3:a:cloud_foundry:bosh:260.2:*:*:*:*:*:*:*",
"cpe:2.3:a:cloud_foundry:bosh:260.3:*:*:*:*:*:*:*",
"cpe:2.3:a:cloud_foundry:bosh:260.4:*:*:*:*:*:*:*",
"cpe:2.3:a:cloud_foundry:bosh:260.5:*:*:*:*:*:*:*",
"cpe:2.3:a:cloud_foundry:bosh:260.6:*:*:*:*:*:*:*",
"cpe:2.3:a:cloud_foundry:bosh:261:*:*:*:*:*:*:*",
"cpe:2.3:a:cloud_foundry:bosh:261.1:*:*:*:*:*:*:*",
"cpe:2.3:a:cloud_foundry:bosh:261.2:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "260"
},
{
"last_affected": "260"
},
{
"introduced": "260.1"
},
{
"last_affected": "260.1"
},
{
"introduced": "260.2"
},
{
"last_affected": "260.2"
},
{
"introduced": "260.3"
},
{
"last_affected": "260.3"
},
{
"introduced": "260.4"
},
{
"last_affected": "260.4"
},
{
"introduced": "260.5"
},
{
"last_affected": "260.5"
},
{
"introduced": "260.6"
},
{
"last_affected": "260.6"
},
{
"introduced": "261"
},
{
"last_affected": "261"
},
{
"introduced": "261.1"
},
{
"last_affected": "261.1"
},
{
"introduced": "261.2"
},
{
"last_affected": "261.2"
}
]
}