PT-2026-46134 · Bosh · Bosh
CVE-2026-41860
·
Published
2026-06-04
·
Updated
2026-07-22
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BOSH versions prior to 282.1.9
Description
An issue in BOSH allows a local attacker to perform Man-in-the-Middle (MITM) attacks to steal Basic-auth credentials or redirect UAA token requests. This occurs because the
create async endpoint() and send http get request synchronous() functions within the HttpRequestHelper hard-code the OpenSSL::SSL::VERIFY NONE setting, which disables SSL certificate verification for outgoing HTTP requests. An attacker with local network access can intercept traffic between the bosh-monitor and the BOSH director or UAA.Recommendations
Update to version 282.1.9 or later.
Fix
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bosh