Affected versions:
- BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 04 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Jun 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local BOSH Monitor TLS Verification Bypass Enables MITM Credential Theft | |
| First Time appeared |
Cloud Foundry
Cloud Foundry bosh |
|
| Vendors & Products |
Cloud Foundry
Cloud Foundry bosh |
Thu, 04 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an attacker to intercept traffic between bosh-monitor and the BOSH director or UAA and steal credentials. Affected versions: - BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later | |
| Weaknesses | CWE-326 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-06-04T12:46:24.952Z
Reserved: 2026-04-22T06:22:10.082Z
Link: CVE-2026-41860
Updated: 2026-06-04T12:46:21.924Z
Status : Awaiting Analysis
Published: 2026-06-04T03:16:20.107
Modified: 2026-06-04T15:35:18.623
Link: CVE-2026-41860
No data.
OpenCVE Enrichment
Updated: 2026-06-04T03:30:04Z