{"id":"CVE-2025-49828","summary":"Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Remote Code Execution","details":"Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.21.1 and Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.1 through 13.4.1 are vulnerable to remote code execution An authenticated attacker who can inject secrets or templates into the Secrets Manager, Self-Hosted database could take advantage of an exposed API endpoint to execute arbitrary Ruby code within the Secrets Manager process. This issue affects both Secrets Manager, Self-Hosted (formerly Conjur Enterprise) and Conjur OSS. Conjur OSS version 1.21.2 and Secrets Manager, Self-Hosted version 13.5 fix the issue.","aliases":["GHSA-93hx-v9pv-qrm4"],"modified":"2026-08-12T03:51:09.001349616Z","published":"2025-07-15T19:35:33.147Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49828.json","unresolved_ranges":[{"extracted_events":[{"introduced":"Conjur OSS \u003e= 1.20.1, \u003c 1.21.2"},{"last_affected":"Conjur OSS \u003e= 1.20.1, \u003c 1.21.2"},{"introduced":"Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) \u003e= 13.1, \u003c 13.5"},{"last_affected":"Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) \u003e= 13.1, \u003c 13.5"}],"source":"AFFECTED_FIELD"},{"source":"DESCRIPTION","extracted_events":[{"introduced":"13.1"},{"fixed":"13.4.1"}]}],"cna_assigner":"GitHub_M","cwe_ids":["CWE-1336"]},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/07/16/7"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/08/08/1"},{"type":"WEB","url":"https://github.com/cyberark/conjur/releases/tag/v1.21.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49828.json"},{"type":"ADVISORY","url":"https://github.com/cyberark/conjur/security/advisories/GHSA-93hx-v9pv-qrm4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-49828"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cyberark/conjur","events":[{"introduced":"13777635cf93eaa58a71e790a93710a6ae45f7ca"},{"fixed":"a579909060c028c84ab60dc0a984e8e386c65c30"}],"database_specific":{"cpe":"cpe:2.3:a:cyberark:conjur:*:*:*:*:open_source:*:*:*","extracted_events":[{"introduced":"1.19.5"},{"fixed":"1.21.1"},{"introduced":"1.20.1"},{"fixed":"1.21.2"}],"source":["DESCRIPTION","CPE_RANGE","REFERENCES"]}}],"versions":["v1.21.1-31","v1.20.1-4405","v1.20.1-4404","v1.20.1-4400","v1.20.1-4395","v1.20.1-4385","v1.20.1-4383","v1.20.1-4378","v1.20.1-4377","v1.20.1-4372","v1.20.1-4368","v1.20.1-4362","v1.20.1-4353","v1.20.0-4262","v1.20.0","v1.20.0-4256","v1.20.0-4255","v1.20.0-4250","v1.20.0-4249","v1.20.0-4238","v1.20.0-4231","v1.20.0-4230","v1.20.0-4229","v1.20.0-4224","v1.20.0-4223","v1.20.0-4222","v1.20.0-4219","v1.20.0-4218","v1.20.0-4214","v1.20.0-4212","v1.20.0-4198","v1.20.0-4191","v1.20.0-4187","v1.20.0-4183","v1.20.0-4180","v1.20.0-4177","v1.20.0-4164","v1.20.0-4161","v1.20.0-4157","v1.20.0-4153","v1.20.0-4132","v1.20.0-4131","v1.20.0-4127","v1.20.0-4126","v1.20.0-4125","v1.20.0-4115","v1.20.0-4107","v1.20.0-4105","v1.20.0-4104","v1.20.0-4095","v1.20.0-4088","v1.20.0-4077","v1.20.0-4076","v1.20.0-4072","v1.20.0-4071","v1.20.0-4069","v1.20.0-4083","v1.19.6-4066","v1.19.6-4065","v1.19.6-4061","v1.19.6-4060","v1.19.6-4056","v1.19.6-4050","v1.19.6-4046","v1.19.6-4045","v1.19.6-4041","v1.19.6-4040","v1.19.6-4038","v1.19.6-4037","v1.19.6-4027","v1.19.6-4023","v1.19.6-4019","v1.19.6-4016","v1.19.6-4004","v1.19.6-4003","v1.19.6-4000","v1.19.6-3999","v1.19.6-3994","v1.19.6-3990","v1.19.6-3989","v1.19.6-3985","v1.19.6-3984","v1.19.6-3979","v1.19.6-3974","v1.19.6-3969","v1.19.6-3968","v1.19.6-3961","v1.19.6-3960","v1.19.6-3955","v1.19.6-3954","v1.19.6-3949","v1.19.6-3948","v1.19.5-3915","v1.19.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-49828.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}