Remote Code Execution Vulnerability in Conjur Secrets Manager by CyberArk
CVE-2025-49828
What is CVE-2025-49828?
A remote code execution vulnerability exists in Conjur, affecting versions 1.19.5 to 1.21.1 of Conjur OSS and versions 13.1 to 13.4.1 of Secrets Manager, Self-Hosted. An authenticated attacker may exploit this vulnerability by injecting malicious secrets or templates into the Secrets Manager, Self-Hosted database. This can be done through an exposed API endpoint, allowing the attacker to execute arbitrary Ruby code within the Secrets Manager process. CyberArk has released versions 1.21.2 for Conjur OSS and 13.5 for Secrets Manager, Self-Hosted, which address this issue.
Affected Version(s)
conjur Conjur OSS >= 1.20.1, < 1.21.2 < Conjur OSS 1.20.1, 1.21.2
conjur Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) >= 13.1, < 13.5 < Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.1, 13.5