216.73.217.22

CVE-2025-49831

· Published 15/07/2025 21:15 · Modified 16/07/2025 14:58

Labels: CVE-2025-49831 2025-07-15CVE-2025-49831CWE-287[email protected]

Essential information

Published
15/07/2025 21:15
Modified
16/07/2025 14:58
Author
Creator
CVSS
9.1 CRITICAL (v3) 9.1 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can reroute authentication requests to a malicious server under the attacker’s control. CyberArk believes there to be very few installations where this issue can be actively exploited, though Secrets Manager, Self-Hosted (formerly Conjur Enterprise) prior to versions 13.5.1 and 13.6.1 and Conjur OSS prior to version 1.22.1 may be affected. Conjur OSS version 1.22.1 and Secrets Manager, Self-Hosted versions 13.5.1 and 13.6.1 fix the issue.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
cyberark / secrets manager cpe:2.3:a:cyberark:secrets_manager:self-hosted:*:*:*:*:*:*:*:*
cyberark / conjur cpe:2.3:a:cyberark:conjur:1.22.0:*:*:*:*:*:*:*:*

References