- Description
- A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones listed below allows an unauthenticated remote attacker in possession of the password to read and manipulate swapped jobs or read and manipulate in- and output data of active jobs. It is also possible to cause a denial-of-service of most functionality of KNIME Business Hub by writing large amounts of data to the object store directly. There are no viable workarounds therefore we strongly recommend to update to one of the following versions of KNIME Business Hub: * 1.13.2 or later * 1.12.3 or later * 1.11.3 or later * 1.10.3 or later
- Source
- security@knime.com
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 8.8
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber
- Severity
- HIGH
- security@knime.com
- CWE-259
- Hype score
- Not currently trending
🚨 CVE-2025-2402 🔴 HIGH (8.8) 🏢 KNIME - KNIME Business Hub 🏗️ 1.13.0 🔗 https://t.co/8jECFofcQN #CyberCron #VulnAlert #InfoSec https://t.co/Fg28908b0p
@cybercronai
31 Mar 2025
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
New post from https://t.co/uXvPWJy6tj (CVE-2025-2402 | KNIME Business Hub up to 1.10.2/1.11.2/1.12.2/1.13.1 Minio hard-coded password) has been published on https://t.co/dtSVHiMJNX
@WolfgangSesin
31 Mar 2025
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-2402 A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones listed below allows an unauthenticated remote attac… https://t.co/7XlJ2aSFl1
@CVEnew
31 Mar 2025
321 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-2402: HIGH] Security Alert: Unauthenticated remote attackers can access and manipulate data in KNIME Business Hub due to hard-coded passwords in some versions. Update to version 1.13.2 or later to mitiga...#cybersecurity,#vulnerability https://t.co/36IV0zw6aq https://t.
@CveFindCom
31 Mar 2025
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes