Access Control Vulnerability in Conda-forge Infrastructure by Anaconda
CVE-2025-31484

9.3CRITICAL

Key Information:

Vendor
CVE Published:
2 April 2025

What is CVE-2025-31484?

A vulnerability in the Conda-forge infrastructure allowed unauthorized access to upload packages to the Conda-forge channel. During a specified period, the wrong token was used for Azure's cf-staging access, enabling any feedstock maintainer to bypass the established upload process. While security logs on anaconda.org were verified, no malicious packages were detected. This incident emphasizes the importance of maintaining strict access controls and proper token management within the infrastructure to mitigate similar risks in the future.

Affected Version(s)

infrastructure >= 2025-02-10, <= 2025-04-01

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.