A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper with the VM list that is written into the NATS authorization file. Stolen credentials grant administrative director access. UsersSync#bosh_api_response_body builds a Net::HTTP client with verify_mode = OpenSSL::SSL::VERIFY_NONE for every director call (/info, /deployments, /deployments/<name>/vms).
Affected versions:
- BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later
Metrics
Affected Vendors & Products
References
History
Thu, 04 Jun 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cloud Foundry
Cloud Foundry bosh |
|
| Vendors & Products |
Cloud Foundry
Cloud Foundry bosh |
Thu, 04 Jun 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Missing TLS in NATS Sync Enables Credential Theft from BOSH Director |
Thu, 04 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper with the VM list that is written into the NATS authorization file. Stolen credentials grant administrative director access. UsersSync#bosh_api_response_body builds a Net::HTTP client with verify_mode = OpenSSL::SSL::VERIFY_NONE for every director call (/info, /deployments, /deployments/<name>/vms). Affected versions: - BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-06-04T01:51:45.608Z
Reserved: 2026-04-22T06:22:10.082Z
Link: CVE-2026-41859
No data.
Status : Received
Published: 2026-06-04T03:16:19.947
Modified: 2026-06-04T03:16:19.947
Link: CVE-2026-41859
No data.
OpenCVE Enrichment
Updated: 2026-06-04T04:00:04Z