CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an attacker to intercept traffic between bosh-monitor and the BOSH director or UAA and steal credentials.
Affected versions:
- BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later
Affected versions:
- BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 04 Jun 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local BOSH Monitor TLS Verification Bypass Enables MITM Credential Theft | |
| First Time appeared |
Cloud Foundry
Cloud Foundry bosh |
|
| Vendors & Products |
Cloud Foundry
Cloud Foundry bosh |
Thu, 04 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an attacker to intercept traffic between bosh-monitor and the BOSH director or UAA and steal credentials. Affected versions: - BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later | |
| Weaknesses | CWE-326 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-06-04T01:40:23.892Z
Reserved: 2026-04-22T06:22:10.082Z
Link: CVE-2026-41860
No data.
Status : Received
Published: 2026-06-04T03:16:20.107
Modified: 2026-06-04T03:16:20.107
Link: CVE-2026-41860
No data.
OpenCVE Enrichment
Updated: 2026-06-04T03:30:04Z
Weaknesses