File Parsing Vulnerability in Conjur Secrets Management by CyberArk
CVE-2025-49830
What is CVE-2025-49830?
In the Conjur Secrets Manager and Self-Hosted environments, an authenticated attacker with the ability to load policy can exploit the YAML parser to reference files on the server. This capability can enable reconnaissance, potentially exposing the folder structure of the Secrets Manager or causing files on the server to be included in the YAML policy during loading. The affected versions prior to updates 13.5.1 and 13.6.1 in Secrets Manager, Self-Hosted, as well as Conjur OSS prior to version 1.22.1, are vulnerable to this issue. Upgrading to the latest versions will mitigate this risk.
Affected Version(s)
conjur Conjur OSS < 1.22.1 < Conjur OSS 1.22.1
conjur Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) < 13.5.1 < Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.5.1
conjur Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) = 13.6 = Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.6