Affected versions:
BOSH Director: All versions prior to v282.1.12
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 08 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cloud Foundry
Cloud Foundry bosh |
|
| CPEs | cpe:2.3:a:cloud_foundry:bosh:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cloud Foundry
Cloud Foundry bosh |
Wed, 27 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cloud Foundry Foundation
Cloud Foundry Foundation bosh Director |
|
| Vendors & Products |
Cloud Foundry Foundation
Cloud Foundry Foundation bosh Director |
Wed, 27 May 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient. inject_compile_log (line 332-339) reads response['value']['result']['compile_log_id'] and format_exception (line 318-325) reads exception['blobstore_id']; both pass the agent-supplied string unmodified to download_and_delete_blob(blob_id) (line 344-349), which calls @resource_manager.get_resource(blob_id) and, in an ensure block, @resource_manager.delete_resource(blob_id). Api::ResourceManager forwards the id straight to blobstore.get(id) / blobstore.delete(id). When the director is configured with the local blobstore provider, Blobstore::LocalClient#object_file_path(oid) is File.join(@blobstore_path, oid) (local_client.rb:54-56) with no normalisation, so oid = "../../jobs/director/config/director.yml" resolves outside the blobstore root. Affected versions: BOSH Director: All versions prior to v282.1.12 | |
| Title | Local Blobstore may allow arbitrary reads/deletes | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-05-27T13:38:30.294Z
Reserved: 2026-04-16T02:19:16.426Z
Link: CVE-2026-41009
Updated: 2026-05-27T13:38:25.472Z
Status : Analyzed
Published: 2026-05-27T08:16:43.647
Modified: 2026-06-17T10:46:02.570
Link: CVE-2026-41009
No data.
OpenCVE Enrichment
Updated: 2026-05-27T10:06:42Z