Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.21.1 and Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.1 through 13.4.1 are vulnerable to remote code execution An authenticated attacker who can inject secrets or templates into the Secrets Manager, Self-Hosted database could take advantage of an exposed API endpoint to execute arbitrary Ruby code within the Secrets Manager process. This issue affects both Secrets Manager, Self-Hosted (formerly Conjur Enterprise) and Conjur OSS. Conjur OSS version 1.21.2 and Secrets Manager, Self-Hosted version 13.5 fix the issue.
References
Link | Resource |
---|---|
https://github.com/cyberark/conjur/releases/tag/v1.21.2 | Release Notes |
https://github.com/cyberark/conjur/security/advisories/GHSA-93hx-v9pv-qrm4 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
11 Sep 2025, 20:38
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CPE | cpe:2.3:a:cyberark:conjur:*:*:*:*:open_source:*:*:* cpe:2.3:a:cyberark:conjur:*:*:*:*:enterprise:*:*:* |
|
First Time |
Cyberark
Cyberark conjur |
|
References | () https://github.com/cyberark/conjur/releases/tag/v1.21.2 - Release Notes | |
References | () https://github.com/cyberark/conjur/security/advisories/GHSA-93hx-v9pv-qrm4 - Vendor Advisory |
15 Jul 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-15 20:15
Updated : 2025-09-11 20:38
NVD link : CVE-2025-49828
Mitre link : CVE-2025-49828
CVE.ORG link : CVE-2025-49828
JSON object : View
Products Affected
cyberark
- conjur
CWE