CVE-2025-49829
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-07-15

Last updated on: 2025-11-04

Assigner: GitHub, Inc.

Description
Conjur provides secrets management and application identity for infrastructure. Missing validations in Secrets Manager, Self-Hosted allows authenticated attackers to inject resources into the database and to bypass permission checks. This issue affects Secrets Manager, Self-Hosted (formerly Conjur Enterprise) prior to versions 13.5.1 and 13.6.1 and Conjur OSS prior to version 1.22.1. Conjur OSS version 1.22.1 and Secrets Manager, Self-Hosted versions 13.5.1 and 13.6.1 fix the issue.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-15
Last Modified
2025-11-04
Generated
2026-05-06
AI Q&A
2025-07-15
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
cyberark conjur to 1.22.1 (exc)
cyberark conjur to 13.5.1 (exc)
cyberark conjur 13.6
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability in Conjur Secrets Manager, Self-Hosted allows authenticated attackers to inject resources into the database and bypass permission checks due to missing validations. It affects versions prior to 13.5.1 and 13.6.1 for Secrets Manager, Self-Hosted and prior to 1.22.1 for Conjur OSS. The issue is fixed in versions 13.5.1, 13.6.1, and 1.22.1 respectively.


How can this vulnerability impact me? :

An attacker who is authenticated could inject unauthorized resources into the database and bypass permission checks, potentially leading to unauthorized access or manipulation of secrets and application identities managed by Conjur. This could compromise the security of infrastructure relying on Conjur for secrets management.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, you should upgrade Conjur Secrets Manager, Self-Hosted to version 13.5.1 or 13.6.1, or Conjur OSS to version 1.22.1 or later, as these versions contain the fix for the issue.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart