Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

137 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.7)0.10%—Cloudfoundry Bosh DirectorAIVmware VcenterAI29/8/20263/9/2026
Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualization infrastructure takeover. An attacker who can intercept traffic…
Pendiente de análisisAlta (8.7)0.53%—MysqlAICloudfoundry UAAAI25/8/202628/9/2026
Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated attacker holding only the zones.write authority to bypass the intended restriction that this authority does not grant access to the privileged uaa…
Pendiente de análisisAlta (7.5)1.6%—Cloudfoundry Bosh CLIAI21/8/202628/8/2026
Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities
Pendiente de análisisMedia (4.2)0.21%—Cloudfoundry Bosh AgentAI6/8/202618/8/2026
Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path ending in .network, and create any missing parent directories with mode 0777 via network Alias on Ubuntu. Affected versions: BOSH agent < v2.847.0…
Pendiente de análisisCrítica (9.3)0.22%—Cloudfoundry UAAAICloudfoundry Cf-deploymentAI9/7/20269/7/2026
A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return forged group memberships that grant themselves admin scopes. This…
AnalizadaAlta (7.7)0.42%—Cloudfoundry Bosh CLI9/7/202613/7/2026
Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation. Affected versions: bosh-cli…
AnalizadaAlta (8.9)0.29%—Cloudfoundry Bosh CLI9/7/202613/7/2026
During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoint is available in the installation manifest. A network attacker can terminate the…
AnalizadaAlta (8.5)0.55%—Cloudfoundry Bosh CLI9/7/202613/7/2026
The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.
AnalizadaAlta (7.1)0.23%—Cloudfoundry Bosh CLI9/7/202613/7/2026
A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versions prior to 7.10.5.
Pendiente de análisisMedia (6.9)0.17%—Cloudfoundry Bpm-releaseAI18/6/202622/6/2026
setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A compromised process inside a bpm container can cause root to chown an arbitrary host file to vcap and append bpm JSON log lines to it. The chown alone lets the attacker take ownership of /etc/shadow and…
AplazadaMedia (5.9)0.47%—Steeltoe Security Authentication CloudfoundrybaseAISteeltoe Security Authentication JwtbearerAISteeltoe Security Authentication OpenidconnectAI17/6/202622/6/2026
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Security.Authentication.CloudFoundryBase prior to version 3.4.0, Steeltoe.Security.Authentication.JwtBearer prior to version 4.2.0, and Steeltoe.Security.Authentication.OpenIdConnect…
Pendiente de análisisCrítica (9)0.16%—Cloudfoundry UAAAICloudfoundry CF DeploymentAI11/6/202617/6/2026
Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser SSO (ACS) when wantAssertionSigned is set to false. Assertions or…
Pendiente de análisisAlta (8.7)0.17%—Cloudfoundry BoshAI4/6/202622/7/2026
ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where name returns @job_meta['name'], a value taken verbatim from the jobs: array of the attacker-supplied release.MF inside the uploaded tarball. These paths are then interpolated into…
Pendiente de análisisAlta (7.1)0.10%—Cloudfoundry BoshAI4/6/202622/7/2026
CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an attacker to intercept traffic between bosh-monitor and the BOSH director or…
Pendiente de análisisAlta (7.1)0.14%—Cloudfoundry BoshAI4/6/202622/7/2026
A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper with the VM list that is written into the NATS authorization file. Stolen credentials grant administrative director access. UsersSync#bosh_api_response_body…
Pendiente de análisisAlta (8.7)0.16%—Cloudfoundry BoshAI4/6/202622/7/2026
PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['name'] comes directly from release.MF inside the uploaded tarball. The string is passed to Bosh::Common::Exec.sh, which executes via %x{} — i.e., /bin/sh -c. No…
Pendiente de análisisCrítica (10)0.46%—Cloudfoundry UAAAICloudfoundry CF DeploymentAI1/6/202622/7/2026
Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed through the public /token_keys endpoint. This endpoint is designed to provide public key material for JWT token…
Pendiente de análisisAlta (7.5)0.65%—Cloudfoundry Cf-auth-proxyAICloudfoundry Log-cache ReleaseAI1/6/202622/7/2026
Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and platform component via minting a JWT that the cf-auth-proxy accepts as a valid logs.admin token. Affected versions: -…
Pendiente de análisisAlta (8.1)0.42%—Cloudfoundry Diego-releaseAICloudfoundry Smb-volume-releaseAICloudfoundry CF DeploymentAI1/6/202622/7/2026
Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells. Affected…
AnalizadaMedia (5)0.20%—Cloudfoundry Cf-deploymentCloudfoundry Routing Release1/5/202617/6/2026
Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send requests to HTTP services on internal networks reachable by the Gorouter,…
Pendiente de análisisAlta (8.6)0.36%—Cloudfoundry UAAAICloudfoundry CF DeploymentAI17/4/202617/6/2026
Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-protected systems. This vulnerability exists when SAML 2.0 bearer assertions are enabled for a client, as the UAA accepts SAML 2.0 bearer assertions that are neither signed nor encrypted. This…
Pendiente de análisisAlta (7.5)0.20%—Cloudfoundry Capi ReleaseAICloudfoundry CF DeploymentAI17/3/202617/6/2026
Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on all platforms allows any user who has bypassed the firewall to potentially replace droplets and therefore applications allowing them to access secure application information.
ModificadaMedia (6.5)0.22%—Cloudfoundry Cf-deploymentCloudfoundry Uaa-release5/3/202617/6/2026
Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.
AnalizadaAlta (7.5)0.20%—Cloudfoundry Cf-deploymentCloudfoundry UAA Release13/5/202517/6/2026
Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.
AplazadaMedia (5.4)0.19%—Cloudfoundry UAAAI31/1/202517/6/2026
A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones.