HIGH🇵🇱 Wersja polska

CVE-2025-2402

CVSS 8.8v4.0pub. 2025-03-31upd. 2025-10-08

A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones listed below allows an unauthenticated remote attacker in possession of the password to read and manipulate swapped jobs or read and manipulate in- and output data of active jobs. It is also possible to cause a denial-of-service of most functionality of KNIME Business Hub by writing large amounts of data to the object store directly. There are no viable workarounds therefore we strongly recommend to update to one of the following versions of KNIME Business Hub: * 1.13.2 or later * 1.12.3 or later * 1.11.3 or later * 1.10.3 or later

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber
  • Knime Business Hub

    APP
    Knime
    < 1.10.31.11.0 – 1.11.3 (excl.)1.12.0 – 1.12.3 (excl.)1.13.0 – 1.13.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-2787HIGH8.7same product

KNIME Business Hub is affected by the Ingress-nginx CVE-2025-1974 ( a.k.a IngressNightmare ) vulnerability whi...

CVE-2024-6598HIGH7.1same product

A denial-of-service attack is possible through the execution functionality of KNIME Business Hub 1.10.0 and 1....

CVE-2025-14262MEDIUM5.3same product

Nieprawidłowa kontrola uprawnień w KNIME Business Hub przed wersją 1.17.0 pozwalała uwierzytelnionemu użytkown...

CVE-2025-11240MEDIUM5.3same product

An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remot...

CVE-2025-3019MEDIUM5.3same product

KNIME Business Hub is affected by several cross-site scripting vulnerabilities in its web pages. If a user cli...