关键漏洞信息 漏洞标题 Missing validations in Secrets Manager, Self-Hosted (formerly Conjur Enterprise) and Conjur OSS 严重性 等级: Moderate CVSS v4 base metrics: 6.0 / 10 影响版本 Conjur OSS (CyberArk): < 1.22.1 Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise): < 13.5.1; 13.6 修复版本 Conjur OSS (CyberArk): 1.22.1 Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise): 13.5.1; 13.6.1 描述 问题: Missing validations in Secrets Manager, Self-Hosted allows authenticated attackers to inject resources into the database and to bypass permission checks. 影响范围: Both Secrets Manager, Self-Hosted (formerly Conjur Enterprise) and Conjur OSS. CVSS v4 基本指标 Exploitability Metrics - Attack Vector: Network - Attack Complexity: Low - Attack Requirements: Present - Privileges Required: Low - User interaction: None Vulnerable System Impact Metrics - Confidentiality: Low - Integrity: High - Availability: None Subsequent System Impact Metrics - Confidentiality: None - Integrity: None - Availability: None CVE ID CVE-2025-49826 弱点 No CWEs