Cloud Foundry bosh-cli
- < v7.10.4
A vulnerability exists in BOSH CLI versions prior to 7.10.4, allowing a compromised BOSH Director to inject arbitrary OpenSSH options into the local SSH process. This occurs when an operator uses non-interactive SSH commands, such as 'bosh ssh -c' or 'bosh logs -f'. The injected options can lead to unauthorized command execution on the operator's workstation.
Exploitation of this vulnerability could result in unauthorized local command execution on the operator's workstation.
Users are advised to upgrade to BOSH CLI version 7.10.4 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.