CVE-2016-4435: Pivotal Bosh Stemcell
Critical severity, CVSS 9.0. EPSS: 0.9% chance of exploitation in the next 30 days.
An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability requires that the unauthenticated clients guess or find a URL matching an existing GUID.
Affected products
- Pivotal Bosh Stemcell: up to and including 3232.4; version 3146.13 only
Published 2017-05-25. Last modified 2026-06-17.