Cloud Foundry BOSH CLI
cpe:2.3:a:pivotal_software:bosh_cli:*:*:*:*:*:*:*
- <= 7.10.4
A shell injection vulnerability has been identified in Cloud Foundry BOSH CLI versions prior to 7.10.5. This vulnerability allows a compromised or malicious BOSH Director to execute arbitrary shell commands on the operator's workstation. The issue arises when the operator uses the 'bosh ssh', 'bosh scp', or 'bosh logs -f' commands with default flags.
Exploitation of this vulnerability could lead to unauthorized execution of shell commands on the operator's workstation, potentially allowing for further manipulation or compromise of the system.
Users are advised to upgrade BOSH CLI to version 7.10.5 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.