Impact
The vulnerability is a path traversal flaw in the BOSH agent that lets an attacker with access to the IaaS‑metadata service write a file to any root‑owned location whose name ends in .network. Because the agent creates missing parent directories with mode 0777, the attacker can also create privileged directories. The flaw can be used to place malicious configuration files or binaries at arbitrary paths, effectively granting root‑level write access and the ability to modify system behaviour. The weakness is cataloged as CWE‑22.
Affected Systems
All versions of the BOSH agent before 2.847.0, as well as the Ubuntu 22.04 LTS (jammy) up to version 1.1202 and the Ubuntu 24.04 LTS (noble) up to version 1.364, are vulnerable. The advisory does not specify a lower bound, implying that every released version before the mentioned thresholds may be affected. The vendor responsible for this component is the CloudFoundry Foundation.
Risk and Exploitability
The CVSS score of 4.2 places the flaw in the medium severity range, and the EPSS score is currently unavailable. The vulnerability is not listed in the CISA KEV catalog. Exploitation is likely possible from an IaaS‑metadata context, which may be remote from the host but requires the attacker to be able to send a specially crafted Alias request to the BOSH agent. The affected configuration is the Unix filesystem and the agent service running on Ubuntu containers or VMs.
OpenCVE Enrichment