CVE-2025-49831
Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) vulnerable to IAM Authenticator Bypass via Mis-configured Network Device
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- June 11, 2025
- Published Date
- July 15, 2025
- Last Updated
- July 15, 2025
- Vendor
- cyberark
- Product
- conjur
- Description
- An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can reroute authentication requests to a malicious server under the attacker’s control. CyberArk believes there to be very few installations where this issue can be actively exploited, though Secrets Manager, Self-Hosted (formerly Conjur Enterprise) prior to versions 13.5.1 and 13.6.1 and Conjur OSS prior to version 1.22.1 may be affected. Conjur OSS version 1.22.1 and Secrets Manager, Self-Hosted versions 13.5.1 and 13.6.1 fix the issue.
CVSS Scores
CVSS v4.0
9.1 - CRITICAL
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS Score
- Score
- 0.07% (Percentile: 23.00%) as of 2025-07-29
SSVC Information
- Exploitation
- none
- Technical Impact
- total
Exploit Status
- Exploited in the Wild
- Yes (2025-07-15 21:40:32 UTC) Source
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CVE | 2025-07-15 21:40:25 UTC |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel