CVE-2025-49829: Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) missing validations
Conjur provides secrets management and application identity for infrastructure. Missing validations in Secrets Manager, Self-Hosted allows authenticated attackers to inject resources into the database and to bypass permission checks. This issue affects Secrets Manager, Self-Hosted (formerly Conjur Enterprise) prior to versions 13.5.1 and 13.6.1 and Conjur OSS prior to version 1.22.1. Conjur OSS version 1.22.1 and Secrets Manager, Self-Hosted versions 13.5.1 and 13.6.1 fix the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49829?
CVE-2025-49829 has a high severity due to the potential for authenticated attackers to inject resources into the database.
How do I fix CVE-2025-49829?
To fix CVE-2025-49829, upgrade to Conjur OSS version 1.22.1 or later, and Conjur Secrets Manager, Self-Hosted version 13.5.2 or 13.6.2.
Who is affected by CVE-2025-49829?
CVE-2025-49829 affects users of Conjur OSS versions up to 1.22.1 and Conjur Secrets Manager, Self-Hosted versions up to 13.5.1 and 13.6.1.
What types of attacks can be conducted due to CVE-2025-49829?
Due to CVE-2025-49829, authenticated attackers can perform database resource injection and bypass permission checks.
Is CVE-2025-49829 a critical security issue?
Yes, CVE-2025-49829 is considered a critical security issue as it compromises the integrity of the secrets management system.