关键漏洞信息 漏洞标题 Path traversal and file disclosure in Secrets Manager, Self-Hosted (formerly Conjur Enterprise) and Conjur OSS 影响版本 Conjur OSS: < 1.22.1 Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise): < 13.5.1; 13.6 修复版本 Conjur OSS: 1.22.1 Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise): 13.5.1; 13.6.1 描述 An authenticated attacker who is able to load policy can use the policy yaml parser to reference files on the Secrets Manager, Self-Hosted server. These references may be used as reconnaissance to better understand the folder structure of the Secrets Manager/Conjur server or to have the yaml parser include files on the server in the yaml that is processed as the policy loads. This issue affects both Secrets Manager, Self-Hosted (formerly Conjur Enterprise) and Conjur OSS. 严重性 CVSS v4 base metrics - Exploitability Metrics - Attack Vector: Network - Attack Complexity: Low - Attack Requirements: None - Privileges Required: Low - User interaction: None - Vulnerable System Impact Metrics - Confidentiality: High - Integrity: None - Availability: None - Subsequent System Impact Metrics - Confidentiality: None - Integrity: None - Availability: None CVE ID CVE-2025-49830 弱点 No CWEs