CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an attacker to intercept traffic between bosh-monitor and the BOSH director or UAA and steal credentials.
Affected versions:
- BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later
References
Configurations
No configuration.
History
04 Jun 2026, 03:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-04 03:16
Updated : 2026-06-04 15:35
NVD link : CVE-2026-41860
Mitre link : CVE-2026-41860
CVE.ORG link : CVE-2026-41860
JSON object : View
Products Affected
No product.
CWE
CWE-326
Inadequate Encryption Strength
