Skip to content

Releases: cloudfoundry/bosh

v282.1.2

30 Oct 06:12

Choose a tag to compare

Package Updates:

  • Updates nginx from 1.29.2 to 1.29.3

Full Changelog: v282.1.1...v282.1.2

v282.1.1

24 Oct 13:59

Choose a tag to compare

What's Changed

  • CI: switch internal CIDR away from 10.0.0.0 by @aramprice in #2634
  • adapt create_vm and attach_disk call for new cpi version 3 by @fmoehler in #2633
  • remove duplicate ip addresses with smaller prefix by @fmoehler in #2636

Full Changelog: v282.1.0...v282.1.1

v282.1.0

17 Oct 13:19

Choose a tag to compare

Full Changelog: v282.0.10...v282.1.0
Same as v282.0.10 which should be a minor release update.

Fixed CVEs:

  • CVE-2025-61770: rack: Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)
  • CVE-2025-61771: rack: Rack's multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)
  • CVE-2025-61772: rack: Rack memory exhaustion denial of service
  • CVE-2025-61919: rubygem-rack: Unbounded read in Rack::Request form parsing can lead to memory exhaustion

Package Updates:

  • Updates nginx from 1.29.1 to 1.29.2

What's Changed

v282.0.10

16 Oct 12:44

Choose a tag to compare

Fixed CVEs:

  • CVE-2025-61770: rack: Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion)
  • CVE-2025-61771: rack: Rack's multipart parser buffers large non‑file fields entirely in memory, enabling DoS (memory exhaustion)
  • CVE-2025-61772: rack: Rack memory exhaustion denial of service
  • CVE-2025-61919: rubygem-rack: Unbounded read in Rack::Request form parsing can lead to memory exhaustion

Package Updates:

  • Updates nginx from 1.29.1 to 1.29.2

What's Changed

Full Changelog: v282.0.9...v282.0.10

v282.0.9

22 Sep 13:48

Choose a tag to compare

Fixed CVEs:

What's Changed

  • Add 'file' package to Dockerfile dependencies for intergration by @ramonskie in #2621

Full Changelog: v282.0.8...v282.0.9

v282.0.8

23 Aug 06:22

Choose a tag to compare

Updates:

  • Updates mariadb-connector from 3.4.5 to 3.4.7

Full Changelog: v282.0.7...v282.0.8

v282.0.7

16 Aug 05:34

Choose a tag to compare

Package Updates:

  • Updates director-ruby-3.3 from 3.3.8 to 3.3.9
  • Updates nginx from 1.29.0 to 1.29.1

Updates:

  • Updates postgresql-13 from 13.21 to 13.22
  • Updates postgresql-15 from 15.13 to 15.14

What's Changed

New Contributors

Full Changelog: v282.0.6...v282.0.7

v282.0.6

27 Jun 23:41

Choose a tag to compare

Package Updates:

  • Updates nginx from 1.28.0 to 1.29.0

Full Changelog: v282.0.5...v282.0.6

v282.0.5

19 Jun 06:43

Choose a tag to compare

Fixed CVEs:

  • CVE-2025-46727: rubygem-rack: Unbounded-Parameter DoS in Rack::QueryParser
  • CVE-2025-49007: rack: rubygem-rack: Rack Content-Disposition Denial of Service

Updates:

  • Updates postgresql-13 from 13.20 to 13.21
  • Updates postgresql-15 from 15.12 to 15.13

What's Changed

Full Changelog: v282.0.4...v282.0.5

v282.0.4

26 Apr 05:13

Choose a tag to compare

Package Updates:

  • Updates nginx from 1.27.5 to 1.28.0

Updates:

  • Updates nats-server from 2.11.1 to 2.11.2

What's Changed

Full Changelog: v282.0.3...v282.0.4