Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an attacker to intercept traffic between bosh-monitor and the BOSH director or UAA and steal credentials. Affected versions: - BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
不充分的加密强度
Vulnerability Title
Cloud Foundry BOSH 安全漏洞
Vulnerability Description
Cloud Foundry BOSH是美国Cloud Foundry公司的一个云基础设施自动化平台。 Cloud Foundry BOSH所有版本及之前版本存在安全漏洞,该漏洞源于HttpRequestHelper硬编码SSL验证关闭,可能导致中间人攻击窃取凭证。
CVSS Information
N/A
Vulnerability Type
N/A