CVE-2025-2402

A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones listed below allows an unauthenticated remote attacker in possession of the password to read and manipulate swapped jobs or read and manipulate in- and output data of active jobs. It is also possible to cause a denial-of-service of most functionality of KNIME Business Hub by writing large amounts of data to the object store directly. There are no viable workarounds therefore we strongly recommend to update to one of the following versions of KNIME Business Hub: * 1.13.2 or later * 1.12.3 or later * 1.11.3 or later * 1.10.3 or later
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:*
cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:*
cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:*
cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:*

History

08 Oct 2025, 17:16

Type Values Removed Values Added
CPE cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:*
First Time Knime business Hub
Knime
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.6
References () https://www.knime.com/security/advisories#CVE-2025-2402 - () https://www.knime.com/security/advisories#CVE-2025-2402 - Vendor Advisory
References () https://github.com/advisories/GHSA-v5p7-3387-gpmg - () https://github.com/advisories/GHSA-v5p7-3387-gpmg - Third Party Advisory

01 Apr 2025, 20:26

Type Values Removed Values Added
Summary
  • (es) Una contraseña no aleatoria y fijada en el código para el almacén de objetos (minio) de KNIME Business Hub, en todas las versiones excepto las que se indican a continuación, permite que un atacante remoto no autenticado que la posea lea y manipule trabajos intercambiados o lea y manipule datos de entrada y salida de trabajos activos. También es posible provocar una denegación de servicio en la mayoría de las funciones de KNIME Business Hub al escribir grandes cantidades de datos directamente en el almacén de objetos. No existen workarounds viables, por lo que recomendamos encarecidamente actualizar a una de las siguientes versiones de KNIME Business Hub: * 1.13.2 o posterior * 1.12.3 o posterior * 1.11.3 o posterior * 1.10.3 o posterior

31 Mar 2025, 13:15

Type Values Removed Values Added
References
  • () https://github.com/advisories/GHSA-v5p7-3387-gpmg -

31 Mar 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-31 07:15

Updated : 2025-10-08 17:16


NVD link : CVE-2025-2402

Mitre link : CVE-2025-2402

CVE.ORG link : CVE-2025-2402


JSON object : View

Products Affected

knime

  • business_hub
CWE
CWE-259

Use of Hard-coded Password