Affected versions:
- BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 04 Jun 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cloud Foundry
Cloud Foundry bosh |
|
| Vendors & Products |
Cloud Foundry
Cloud Foundry bosh |
Thu, 04 Jun 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Missing TLS in NATS Sync Enables Credential Theft from BOSH Director |
Thu, 04 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper with the VM list that is written into the NATS authorization file. Stolen credentials grant administrative director access. UsersSync#bosh_api_response_body builds a Net::HTTP client with verify_mode = OpenSSL::SSL::VERIFY_NONE for every director call (/info, /deployments, /deployments/<name>/vms). Affected versions: - BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-06-04T01:51:45.608Z
Reserved: 2026-04-22T06:22:10.082Z
Link: CVE-2026-41859
No data.
Status : Received
Published: 2026-06-04T03:16:19.947
Modified: 2026-06-04T03:16:19.947
Link: CVE-2026-41859
No data.
OpenCVE Enrichment
Updated: 2026-06-04T04:00:04Z