File Parsing Vulnerability in Conjur Secrets Management by CyberArk
CVE-2025-49830

7.1HIGH

Key Information:

Vendor

Cyberark

Status
Vendor
CVE Published:
15 July 2025

What is CVE-2025-49830?

In the Conjur Secrets Manager and Self-Hosted environments, an authenticated attacker with the ability to load policy can exploit the YAML parser to reference files on the server. This capability can enable reconnaissance, potentially exposing the folder structure of the Secrets Manager or causing files on the server to be included in the YAML policy during loading. The affected versions prior to updates 13.5.1 and 13.6.1 in Secrets Manager, Self-Hosted, as well as Conjur OSS prior to version 1.22.1, are vulnerable to this issue. Upgrading to the latest versions will mitigate this risk.

Affected Version(s)

conjur Conjur OSS < 1.22.1 < Conjur OSS 1.22.1

conjur Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) < 13.5.1 < Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.5.1

conjur Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) = 13.6 = Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.6

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49830 : File Parsing Vulnerability in Conjur Secrets Management by CyberArk