Network Misconfiguration Vulnerability in CyberArk Secrets Manager and Conjur OSS
CVE-2025-49831
What is CVE-2025-49831?
A misconfigured network device in Secrets Manager, Self-Hosted installations may allow an attacker to reroute authentication requests to a controlled malicious server. This affects specific versions of Secrets Manager and Conjur OSS prior to their resolved updates, specifically versions 13.5.1, 13.6.1, and 1.22.1. The vulnerability underscores the importance of secure configuration practices to protect sensitive authentication information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
conjur Conjur OSS < 1.22.1 < Conjur OSS 1.22.1
conjur Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) < 13.5.1 < Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.5.1
conjur Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) = 13.6 = Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.6
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
