Affected versions: bpm-release, all versions prior to v1.4.30.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 24 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cloudfoundry
Cloudfoundry bpm-release |
|
| Vendors & Products |
Cloudfoundry
Cloudfoundry bpm-release |
Thu, 18 Jun 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Container-to-host privilege escalation via symlink in Cloud Foundry BPM setupBpmLogs |
Thu, 18 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A compromised process inside a bpm container can cause root to chown an arbitrary host file to vcap and append bpm JSON log lines to it. The chown alone lets the attacker take ownership of /etc/shadow and read every password hash on the host via the read-only /etc bind mount. This is a container-to-host confidentiality break affecting every bpm-managed job. Affected versions: bpm-release, all versions prior to v1.4.30. | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-06-18T19:08:11.771Z
Reserved: 2026-05-20T10:00:48.931Z
Link: CVE-2026-47833
Updated: 2026-06-18T18:42:59.082Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T20:41:59Z