Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2760▲ 8 respecto a la semana anterior
Críticas / altas1467▲ 291 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
137 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.10% | — | Cloudfoundry Bosh DirectorAIVmware VcenterAI | 29/8/2026 | 3/9/2026 | Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualization infrastructure takeover. An attacker who can intercept traffic… | |
| Pendiente de análisis | Alta (8.7) | 0.53% | — | MysqlAICloudfoundry UAAAI | 25/8/2026 | 28/9/2026 | Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated attacker holding only the zones.write authority to bypass the intended restriction that this authority does not grant access to the privileged uaa… | |
| Pendiente de análisis | Alta (7.5) | 1.6% | — | Cloudfoundry Bosh CLIAI | 21/8/2026 | 28/8/2026 | Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities | |
| Pendiente de análisis | Media (4.2) | 0.21% | — | Cloudfoundry Bosh AgentAI | 6/8/2026 | 18/8/2026 | Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path ending in .network, and create any missing parent directories with mode 0777 via network Alias on Ubuntu. Affected versions: BOSH agent < v2.847.0… | |
| Pendiente de análisis | Crítica (9.3) | 0.22% | — | Cloudfoundry UAAAICloudfoundry Cf-deploymentAI | 9/7/2026 | 9/7/2026 | A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return forged group memberships that grant themselves admin scopes. This… | |
| Analizada | Alta (7.7) | 0.42% | — | Cloudfoundry Bosh CLI | 9/7/2026 | 13/7/2026 | Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation. Affected versions: bosh-cli… | |
| Analizada | Alta (8.9) | 0.29% | — | Cloudfoundry Bosh CLI | 9/7/2026 | 13/7/2026 | During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoint is available in the installation manifest. A network attacker can terminate the… | |
| Analizada | Alta (8.5) | 0.55% | — | Cloudfoundry Bosh CLI | 9/7/2026 | 13/7/2026 | The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4. | |
| Analizada | Alta (7.1) | 0.23% | — | Cloudfoundry Bosh CLI | 9/7/2026 | 13/7/2026 | A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versions prior to 7.10.5. | |
| Pendiente de análisis | Media (6.9) | 0.17% | — | Cloudfoundry Bpm-releaseAI | 18/6/2026 | 22/6/2026 | setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A compromised process inside a bpm container can cause root to chown an arbitrary host file to vcap and append bpm JSON log lines to it. The chown alone lets the attacker take ownership of /etc/shadow and… | |
| Aplazada | Media (5.9) | 0.47% | — | Steeltoe Security Authentication CloudfoundrybaseAISteeltoe Security Authentication JwtbearerAISteeltoe Security Authentication OpenidconnectAI | 17/6/2026 | 22/6/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Security.Authentication.CloudFoundryBase prior to version 3.4.0, Steeltoe.Security.Authentication.JwtBearer prior to version 4.2.0, and Steeltoe.Security.Authentication.OpenIdConnect… | |
| Pendiente de análisis | Crítica (9) | 0.16% | — | Cloudfoundry UAAAICloudfoundry CF DeploymentAI | 11/6/2026 | 17/6/2026 | Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser SSO (ACS) when wantAssertionSigned is set to false. Assertions or… | |
| Pendiente de análisis | Alta (8.7) | 0.17% | — | Cloudfoundry BoshAI | 4/6/2026 | 22/7/2026 | ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where name returns @job_meta['name'], a value taken verbatim from the jobs: array of the attacker-supplied release.MF inside the uploaded tarball. These paths are then interpolated into… | |
| Pendiente de análisis | Alta (7.1) | 0.10% | — | Cloudfoundry BoshAI | 4/6/2026 | 22/7/2026 | CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an attacker to intercept traffic between bosh-monitor and the BOSH director or… | |
| Pendiente de análisis | Alta (7.1) | 0.14% | — | Cloudfoundry BoshAI | 4/6/2026 | 22/7/2026 | A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper with the VM list that is written into the NATS authorization file. Stolen credentials grant administrative director access. UsersSync#bosh_api_response_body… | |
| Pendiente de análisis | Alta (8.7) | 0.16% | — | Cloudfoundry BoshAI | 4/6/2026 | 22/7/2026 | PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['name'] comes directly from release.MF inside the uploaded tarball. The string is passed to Bosh::Common::Exec.sh, which executes via %x{} — i.e., /bin/sh -c. No… | |
| Pendiente de análisis | Crítica (10) | 0.46% | — | Cloudfoundry UAAAICloudfoundry CF DeploymentAI | 1/6/2026 | 22/7/2026 | Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed through the public /token_keys endpoint. This endpoint is designed to provide public key material for JWT token… | |
| Pendiente de análisis | Alta (7.5) | 0.65% | — | Cloudfoundry Cf-auth-proxyAICloudfoundry Log-cache ReleaseAI | 1/6/2026 | 22/7/2026 | Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and platform component via minting a JWT that the cf-auth-proxy accepts as a valid logs.admin token. Affected versions: -… | |
| Pendiente de análisis | Alta (8.1) | 0.42% | — | Cloudfoundry Diego-releaseAICloudfoundry Smb-volume-releaseAICloudfoundry CF DeploymentAI | 1/6/2026 | 22/7/2026 | Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells. Affected… | |
| Analizada | Media (5) | 0.20% | — | Cloudfoundry Cf-deploymentCloudfoundry Routing Release | 1/5/2026 | 17/6/2026 | Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send requests to HTTP services on internal networks reachable by the Gorouter,… | |
| Pendiente de análisis | Alta (8.6) | 0.36% | — | Cloudfoundry UAAAICloudfoundry CF DeploymentAI | 17/4/2026 | 17/6/2026 | Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-protected systems. This vulnerability exists when SAML 2.0 bearer assertions are enabled for a client, as the UAA accepts SAML 2.0 bearer assertions that are neither signed nor encrypted. This… | |
| Pendiente de análisis | Alta (7.5) | 0.20% | — | Cloudfoundry Capi ReleaseAICloudfoundry CF DeploymentAI | 17/3/2026 | 17/6/2026 | Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on all platforms allows any user who has bypassed the firewall to potentially replace droplets and therefore applications allowing them to access secure application information. | |
| Modificada | Media (6.5) | 0.23% | — | Cloudfoundry Cf-deploymentCloudfoundry Uaa-release | 5/3/2026 | 17/6/2026 | Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0. | |
| Analizada | Alta (7.5) | 0.20% | — | Cloudfoundry Cf-deploymentCloudfoundry UAA Release | 13/5/2025 | 17/6/2026 | Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs. | |
| Aplazada | Media (5.4) | 0.19% | — | Cloudfoundry UAAAI | 31/1/2025 | 17/6/2026 | A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones. |