Bypass of IAM Authenticator in Secrets Manager, Self-Hosted (formerly Conjur Enterprise) and Conjur OSS
Package
Conjur OSS
(CyberArk)
Affected versions
1.19.5-1.22.0
Patched versions
1.22.1
Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise)
(CyberArk)
13.1-13.5; 13.6
13.5.1; 13.6.1
An attacker who can manipulate the headers signed by AWS can take advantage of a malformed regular expression to redirect the authentication validation request that Secrets Manager, Self-Hosted (formerly Conjur Enterprise) sends to AWS to a malicious server controlled by the attacker. This redirection could result in a bypass of the Secrets Manager, Self-Hosted IAM Authenticator, granting the attacker the permissions granted to the client whose request was manipulated. This issue affects both Secrets Manager, Self-Hosted (formerly Conjur Enterprise) and Conjur OSS. CyberArk thanks Yarden Porat and Shahar Tal of Cyata Security for responsibly disclosing this issue.