Executive brief
A vulnerability in the BOSH Process Manager (bpm) allows a compromised container to gain unauthorized access to sensitive files on the host operating system. By manipulating log files, an attacker can take ownership of critical system files like the password database. This allows the attacker to read password hashes for all users on the host, leading to a significant breach of confidentiality and potential full system takeover.
Technical details
A symlink following vulnerability (CWE-59) exists in the setupBpmLogs component of Cloud Foundry bpm-release. When opening and changing ownership of the bpm.log file, the process (running as root) follows symbolic links created by a compromised process within the container. An attacker can point these symlinks to arbitrary host files, such as /etc/shadow. This causes the root process to change the ownership of the target host file to the 'vcap' user, allowing the attacker to read sensitive data (like password hashes) through the read-only /etc bind mount. The issue is fixed in bpm-release v1.4.30.
Affected products
- Cloud Foundry Foundation bpm-release versions prior to v1.4.30
Timeline
- 2026-06-18: disclosed
- 2026-06-18: advisory
- 2026-06-18: patched: Fixed in v1.4.30