Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Argument Injection in BOSH CLI Allows Local Command Execution on Operator Workstations via Compromised Director
Vulnerability Description
Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation. Affected versions: bosh-cli versions prior to v7.10.4.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
N/A
Vulnerability Title
Cloud Foundry Foundation BOSH 命令注入漏洞
Vulnerability Description
Cloud Foundry Foundation BOSH是Cloud Foundry Foundation基金会的开源PaaS平台。 Cloud Foundry Foundation BOSH 7.10.4之前版本存在命令注入漏洞,该漏洞源于参数注入问题,可能导致攻击者通过已妥协的BOSH Director向本地生成的ssh进程注入任意OpenSSH选项,从而导致在操作员的工作站上执行本地命令。
CVSS Information
N/A
Vulnerability Type
N/A