PT-2025-13656 · Knime · Knime Business Hub

Published

2025-03-31

·

Updated

2025-04-01

·

CVE-2025-2402

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:N/AU:Y/R:U/V:C/RE:M/U:Amber
Name of the Vulnerable Software and Affected Versions KNIME Business Hub versions prior to 1.10.3 KNIME Business Hub versions prior to 1.11.3 KNIME Business Hub versions prior to 1.12.3 KNIME Business Hub versions prior to 1.13.2
Description A hard-coded, non-random password for the object store (minio) of KNIME Business Hub allows an unauthenticated remote attacker in possession of the password to read and manipulate swapped jobs or read and manipulate in- and output data of active jobs. It is also possible to cause a denial-of-service of most functionality of KNIME Business Hub by writing large amounts of data to the object store directly.
Recommendations Update to version 1.10.3 or later. Update to version 1.11.3 or later. Update to version 1.12.3 or later. Update to version 1.13.2 or later.

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2025-2402
GHSA-V5P7-3387-GPMG

Affected Products

Knime Business Hub