Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.10% | — | Cloudfoundry Bosh DirectorAIVmware VcenterAI | 29/8/2026 | 3/9/2026 | Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualization infrastructure takeover. An attacker who can intercept traffic… | |
| Pendiente de análisis | Alta (7.5) | 1.6% | — | Cloudfoundry Bosh CLIAI | 21/8/2026 | 28/8/2026 | Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities | |
| Pendiente de análisis | Media (4.2) | 0.21% | — | Cloudfoundry Bosh AgentAI | 6/8/2026 | 18/8/2026 | Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path ending in .network, and create any missing parent directories with mode 0777 via network Alias on Ubuntu. Affected versions: BOSH agent < v2.847.0… | |
| Pendiente de análisis | Alta (7.7) | 0.32% | — | Bosh Windows Stemcell BuilderAI | 9/7/2026 | 9/7/2026 | Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attacker to brute-force the resulting SSH login via TCP/22. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98. | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | Bosh-ecosystem Bosh-windows-stemcell-builderAI | 9/7/2026 | 9/7/2026 | Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next service restart or reboot. This can lead to full host control. Affected… | |
| Analizada | Alta (7.7) | 0.42% | — | Cloudfoundry Bosh CLI | 9/7/2026 | 13/7/2026 | Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation. Affected versions: bosh-cli… | |
| Analizada | Alta (8.9) | 0.29% | — | Cloudfoundry Bosh CLI | 9/7/2026 | 13/7/2026 | During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoint is available in the installation manifest. A network attacker can terminate the… | |
| Analizada | Alta (8.5) | 0.55% | — | Cloudfoundry Bosh CLI | 9/7/2026 | 13/7/2026 | The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4. | |
| Analizada | Alta (7.1) | 0.23% | — | Cloudfoundry Bosh CLI | 9/7/2026 | 13/7/2026 | A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versions prior to 7.10.5. | |
| Pendiente de análisis | Alta (8.7) | 0.17% | — | Cloudfoundry BoshAI | 4/6/2026 | 22/7/2026 | ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where name returns @job_meta['name'], a value taken verbatim from the jobs: array of the attacker-supplied release.MF inside the uploaded tarball. These paths are then interpolated into… | |
| Pendiente de análisis | Alta (7.1) | 0.10% | — | Cloudfoundry BoshAI | 4/6/2026 | 22/7/2026 | CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an attacker to intercept traffic between bosh-monitor and the BOSH director or… | |
| Pendiente de análisis | Alta (7.1) | 0.14% | — | Cloudfoundry BoshAI | 4/6/2026 | 22/7/2026 | A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper with the VM list that is written into the NATS authorization file. Stolen credentials grant administrative director access. UsersSync#bosh_api_response_body… | |
| Pendiente de análisis | Alta (7.5) | 0.42% | — | Bosh-ecosystem Windows Utilities ReleaseAI | 4/6/2026 | 22/7/2026 | Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities-release allows a network attacker to estimate VM boot time and reconstruct a small candidate list to recover the Administrator password. The randomize_password job exists solely to lock the local… | |
| Pendiente de análisis | Alta (8.7) | 0.16% | — | Cloudfoundry BoshAI | 4/6/2026 | 22/7/2026 | PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['name'] comes directly from release.MF inside the uploaded tarball. The string is passed to Bosh::Common::Exec.sh, which executes via %x{} — i.e., /bin/sh -c. No… | |
| Analizada | Media (6.8) | 0.11% | — | Cloud Foundry Bosh | 27/5/2026 | 17/6/2026 | AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every response, which reads response['value']['result']['compile_log_id'] (line 332-338) and passes it to download_and_delete_blob. Separately, any response containing 'exception' goes through… | |
| Analizada | Media (4.3) | 0.13% | — | Cloud Foundry Bosh | 27/5/2026 | 17/6/2026 | When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient. inject_compile_log (line 332-339) reads response['value']['result']['compile_log_id'] and format_exception (line 318-325) reads exception['blobstore_id']; both pass the agent-supplied string… | |
| Aplazada | Crítica (9.1) | 0.55% | — | Cloudfoundry Haproxy-boshreleaseAICloudfoundry Routing-releaseAICloudfoundry Cloud FoundryAI | 3/7/2024 | 17/6/2026 | When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authentication to Cloud Foundry applications. You are affected if you have route-services enabled in routing-release and have configured the… | |
| Modificada | Crítica (9.8) | 2.6% | — | Vmware Bosh EditorVmware Cloudfoundry Manifest YML SupportVmware Concourse CI Pipeline EditorVmware Spring Boot Tools+1 | 4/11/2022 | 17/6/2026 | Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing support. This library allows for some special syntax in the… | |
| Modificada | Media (6.5) | 0.92% | — | Cloud Foundry Bosh System Metrics Server | 2/10/2020 | 17/6/2026 | BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details). | |
| Modificada | Alta (7.8) | 0.29% | — | Cloud Foundry Bosh | 19/6/2019 | 17/6/2026 | Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticated malicious user may read any credentials that are contained in a BOSH manifest. | |
| Modificada | Alta (7.1) | 0.58% | — | Cloudfoundry Bosh Backup AND Restore | 24/4/2019 | 17/6/2026 | Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup scripts in BOSH. A remote authenticated malicious user can modify the metadata file of a Bosh Backup and Restore job to request extra backup files from different jobs upon restore. The exploited hooks in… | |
| Modificada | Alta (8.1) | 1.5% | — | Cloud Foundry Bosh | 5/10/2018 | 17/6/2026 | Cloud Foundry BOSH, versions v264 prior to v264.14.0 and v265 prior to v265.7.0 and v266 prior to v266.8.0 and v267 prior to v267.2.0, allows refresh tokens to be as access tokens when using UAA for authentication. A remote attacker with an admin refresh token given by UAA can be used to access BOSH resources without… | |
| Modificada | Alta (8.8) | 0.97% | — | Pivotal Software Bosh CLI | 27/3/2018 | 17/6/2026 | Cloud Foundry BOSH CLI, versions prior to v3.0.1, contains an improper access control vulnerability. A user with access to an instance using the BOSH CLI can access the BOSH CLI configuration file and use its contents to perform authenticated requests to BOSH. | |
| Modificada | Media (6.1) | 0.83% | — | Cloudfoundry Cf-releasePivotal UAAPivotal UAA Bosh | 4/1/2018 | 17/6/2026 | An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0. A cross-site scripting (XSS) attack is possible in the clientId parameter of a request to the UAA OpenID… | |
| Modificada | Media (6.6) | 0.88% | — | Pivotal Software Cloud Foundry UAACloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry CF | 10/7/2017 | 17/6/2026 | In Cloud Foundry cf-release versions prior to v264; UAA release all versions of UAA v2.x.x, 3.6.x versions prior to v3.6.13, 3.9.x versions prior to v3.9.15, 3.20.x versions prior to v3.20.0, and other versions prior to v4.4.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.17, 24.x versions prior to… |