Network Misconfiguration Vulnerability in CyberArk Secrets Manager and Conjur OSS
CVE-2025-49831
What is CVE-2025-49831?
A misconfigured network device in Secrets Manager, Self-Hosted installations may allow an attacker to reroute authentication requests to a controlled malicious server. This affects specific versions of Secrets Manager and Conjur OSS prior to their resolved updates, specifically versions 13.5.1, 13.6.1, and 1.22.1. The vulnerability underscores the importance of secure configuration practices to protect sensitive authentication information.
Affected Version(s)
conjur Conjur OSS < 1.22.1 < Conjur OSS 1.22.1
conjur Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) < 13.5.1 < Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.5.1
conjur Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) = 13.6 = Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.6