CVE-2025-49828: Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Remote Code Execution
Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.21.1 and Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.1 through 13.4.1 are vulnerable to remote code execution An authenticated attacker who can inject secrets or templates into the Secrets Manager, Self-Hosted database could take advantage of an exposed API endpoint to execute arbitrary Ruby code within the Secrets Manager process. This issue affects both Secrets Manager, Self-Hosted (formerly Conjur Enterprise) and Conjur OSS. Conjur OSS version 1.21.2 and Secrets Manager, Self-Hosted version 13.5 fix the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49828?
CVE-2025-49828 is rated as a critical vulnerability due to its potential for remote code execution by authenticated attackers.
How do I fix CVE-2025-49828?
To fix CVE-2025-49828, upgrade Conjur OSS to version 1.21.2 or later and Conjur Secrets Manager, Self-Hosted to version 13.4.2 or later.
What versions of Conjur are affected by CVE-2025-49828?
CVE-2025-49828 affects Conjur OSS versions 1.19.5 through 1.21.1 and Secrets Manager, Self-Hosted versions 13.1 through 13.4.1.
Who can exploit CVE-2025-49828?
Authenticated attackers can exploit CVE-2025-49828 to execute remote code on affected systems.
What types of systems are impacted by CVE-2025-49828?
CVE-2025-49828 impacts systems running Conjur OSS and Conjur Secrets Manager, Self-Hosted.