CyberArk Conjur OSS and Secrets Manager Remote Code Execution Vulnerability
Vulnerability
A remote code execution vulnerability has been identified in CyberArk Conjur OSS versions 1.19.5 prior to 1.21.1 and in Secrets Manager, Self-Hosted (formerly Conjur Enterprise) versions 13.1 through 13.4.1. This vulnerability allows an authenticated attacker who can inject secrets or templates into the Secrets Manager database to execute arbitrary Ruby code within the Secrets Manager process, exploiting an exposed API endpoint.
Impact
Exploitation of this vulnerability allows for remote code execution within the Secrets Manager process or Conjur OSS, depending on the product in use.
Remediation
Users can upgrade to Conjur OSS version 1.21.2 or Secrets Manager, Self-Hosted version 13.5 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
