Impact
A malicious or compromised BOSH Director can inject arbitrary shell commands into an operator’s workstation when the operator runs commands such as bosh ssh, bosh scp, or bosh logs –f with the default flags. This injection flaw (CWE‑78) allows a remote adversary to execute any local command on the operator’s machine, compromising confidentiality, integrity, and availability.
Affected Systems
CloudFoundry BOSH CLI versions prior to 7.10.5 are vulnerable. Operators using any of those versions to interact with a BOSH Director—regardless of network configuration—are at risk.
Risk and Exploitability
The vulnerability is remote; exploitation requires a compromised BOSH Director and the operator to invoke the CLI with default flags. Once injected commands are processed, arbitrary local execution occurs. The CVSS score of 7.1 signals moderate‑to‑high severity, while the EPSS score of <1% indicates a low but non‑zero likelihood of exploitation. The issue is not listed in CISA KEV.
OpenCVE Enrichment