CyberArk Conjur OSS and Secrets Manager Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in CyberArk Conjur OSS versions 1.19.5 prior to 1.21.1 and in Secrets Manager, Self-Hosted (formerly Conjur Enterprise) versions 13.1 through 13.4.1. This vulnerability allows an authenticated attacker who can inject secrets or templates into the Secrets Manager database to execute arbitrary Ruby code within the Secrets Manager process, exploiting an exposed API endpoint.

Impact

Exploitation of this vulnerability allows for remote code execution within the Secrets Manager process or Conjur OSS, depending on the product in use.

Remediation

Users can upgrade to Conjur OSS version 1.21.2 or Secrets Manager, Self-Hosted version 13.5 to address this vulnerability.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.8
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.