An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can reroute authentication requests to a malicious server under the attacker’s control. CyberArk believes there to be very few installations where this issue can be actively exploited, though Secrets Manager, Self-Hosted (formerly Conjur Enterprise) prior to versions 13.5.1 and 13.6.1 and Conjur OSS prior to version 1.22.1 may be affected. Conjur OSS version 1.22.1 and Secrets Manager, Self-Hosted versions 13.5.1 and 13.6.1 fix the issue.
In environments where network traffic from Secrets Manager to AWS is routed through a misconfigured network device (e.g., proxy or router), an attacker can take control of the transmission path and redirect authentication requests to their own malicious server. This server can impersonate the correct AWS endpoint and accept or manipulate authentication requests. The vulnerability is classified as CWE-287 (improper authentication), meaning that the identity verification mechanism can be effectively bypassed without knowledge of valid credentials.
An attacker can gain unauthorized access to the secrets management system, potentially reading or taking control of stored credentials and secrets. The breach of confidentiality and integrity of data stored in the system is high (VC:H, VI:H according to CVSS vector).
Software should be updated to Conjur OSS version 1.22.1 or later and Secrets Manager Self-Hosted to version 13.5.1 or 13.6.1 (or later). Additionally, it is recommended to audit the configuration of network devices handling traffic between Secrets Manager and AWS to detect and eliminate any misconfigurations that enable traffic redirection.
CyberArk Secrets Manager, Self-Hosted (formerly Conjur Enterprise) in versions earlier than 13.5.1 and 13.6.1, and Conjur OSS in versions earlier than 1.22.1. Affects only Self-Hosted installations where traffic to AWS is routed through a misconfigured network device.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCyberark Conjur
APPCyberark13.6< 1.22.1< 13.5.1
Related vulnerabilities
CyberArk Conjur — bypass uwierzytelniania IAM przez błędne wyrażenie regularne
Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 thr...
Conjur provides secrets management and application identity for infrastructure. An authenticated attacker who ...
Conjur provides secrets management and application identity for infrastructure. Missing validations in Secrets...
XXE w CyberArk Enterprise Password Vault — odczyt plików i bypass uwierzytelnienia