Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.22.0 and Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.1 through 13.5 and 13.6 are vulnerable to bypass of the IAM authenticator. An attacker who can manipulate the headers signed by AWS can take advantage of a malformed regular expression to redirect the authentication validation request that Secrets Manager, Self-Hosted sends to AWS to a malicious server controlled by the attacker. This redirection could result in a bypass of the Secrets Manager, Self-Hosted IAM Authenticator, granting the attacker the permissions granted to the client whose request was manipulated. This issue affects both Secrets Manager, Self-Hosted (formerly Conjur Enterprise) and Conjur OSS. Conjur OSS version 1.22.1 and Secrets Manager, Self-Hosted versions 13.5.1 and 13.6.1 fix the issue.
The vulnerability (CWE-807 — Reliance on Untrusted Inputs in a Security Decision) results from the use of a flawed regular expression when processing headers signed by AWS. An attacker who is able to manipulate these headers can cause Conjur to redirect the validation request to a malicious server controlled by the attacker instead of sending it to the legitimate AWS service. This server can return a fabricated response, resulting in successful identity verification and granting the attacker the privileges assigned to the manipulated client.
An attacker can completely bypass the IAM authentication mechanism and obtain privileges assigned to the client identity whose request was manipulated, which means unauthorized access to managed secrets and infrastructure.
Update to Conjur OSS version 1.22.1 or Secrets Manager, Self-Hosted 13.5.1 or 13.6.1, which contain patches eliminating the vulnerability. Patches are available in the CyberArk GitHub repository and through the vendor's official distribution channels.
Conjur OSS versions 1.19.5 – 1.22.0 and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) versions 13.1 – 13.5 and 13.6.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCyberark Conjur
APPCyberark1.19.5 – 1.22.1 (excl.)13.1 – 13.5.1 (excl.)
Related vulnerabilities
CyberArk Conjur – pominięcie uwierzytelnienia przez przekierowanie ruchu (Auth Bypass)
Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 thr...
Conjur provides secrets management and application identity for infrastructure. An authenticated attacker who ...
Conjur provides secrets management and application identity for infrastructure. Missing validations in Secrets...
XXE w CyberArk Enterprise Password Vault — odczyt plików i bypass uwierzytelnienia