Loading HuntDB...

GHSA-xr6m-h5m8-p48r

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup scripts in BOSH. A remote authenticated malicious user can modify the metadata file of a Bosh Backup and Restore job to request extra backup files from different jobs upon restore. The exploited hooks in this metadata script were only maintained in the cfcr-etcd-release, so clusters deployed with the BBR job for etcd in this release are vulnerable.

Related CVEs

Key Information

GHSA ID
GHSA-xr6m-h5m8-p48r
Published
May 24, 2022 4:44 PM
Last Modified
April 4, 2024 12:04 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 7, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.