CRITICAL🇵🇱 Wersja polska

CVE-2025-49831

CVSS 9.1v4.0pub. 2025-07-15upd. 2025-11-04

An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can reroute authentication requests to a malicious server under the attacker’s control. CyberArk believes there to be very few installations where this issue can be actively exploited, though Secrets Manager, Self-Hosted (formerly Conjur Enterprise) prior to versions 13.5.1 and 13.6.1 and Conjur OSS prior to version 1.22.1 may be affected. Conjur OSS version 1.22.1 and Secrets Manager, Self-Hosted versions 13.5.1 and 13.6.1 fix the issue.

🤖 AI Analysis
How it works

In environments where network traffic from Secrets Manager to AWS is routed through a misconfigured network device (e.g., proxy or router), an attacker can take control of the transmission path and redirect authentication requests to their own malicious server. This server can impersonate the correct AWS endpoint and accept or manipulate authentication requests. The vulnerability is classified as CWE-287 (improper authentication), meaning that the identity verification mechanism can be effectively bypassed without knowledge of valid credentials.

Impact

An attacker can gain unauthorized access to the secrets management system, potentially reading or taking control of stored credentials and secrets. The breach of confidentiality and integrity of data stored in the system is high (VC:H, VI:H according to CVSS vector).

Mitigation & patch

Software should be updated to Conjur OSS version 1.22.1 or later and Secrets Manager Self-Hosted to version 13.5.1 or 13.6.1 (or later). Additionally, it is recommended to audit the configuration of network devices handling traffic between Secrets Manager and AWS to detect and eliminate any misconfigurations that enable traffic redirection.

Who is affected

CyberArk Secrets Manager, Self-Hosted (formerly Conjur Enterprise) in versions earlier than 13.5.1 and 13.6.1, and Conjur OSS in versions earlier than 1.22.1. Affects only Self-Hosted installations where traffic to AWS is routed through a misconfigured network device.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Cyberark Conjur

    APP
    Cyberark
    13.6< 1.22.1< 13.5.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-49827CRITICAL9.1PL ✓same product

CyberArk Conjur — bypass uwierzytelniania IAM przez błędne wyrażenie regularne

CVE-2025-49828HIGH8.6same product

Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 thr...

CVE-2025-49830HIGH7.1same product

Conjur provides secrets management and application identity for infrastructure. An authenticated attacker who ...

CVE-2025-49829MEDIUM6.0same product

Conjur provides secrets management and application identity for infrastructure. Missing validations in Secrets...

CVE-2019-7442CRITICAL9.8PL ✓same vendor

XXE w CyberArk Enterprise Password Vault — odczyt plików i bypass uwierzytelnienia