CVE-2025-2402

A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones listed below allows an unauthenticated remote attacker in possession of the password to read and manipulate swapped jobs or read and manipulate in- and output data of active jobs. It is also possible to cause a denial-of-service of most functionality of KNIME Business Hub by writing large amounts of data to the object store directly. There are no viable workarounds therefore we strongly recommend to update to one of the following versions of KNIME Business Hub: * 1.13.2 or later * 1.12.3 or later * 1.11.3 or later * 1.10.3 or later
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:*
cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:*
cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:*
cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-03-31 07:15

Updated : 2025-10-08 17:16


NVD link : CVE-2025-2402

Mitre link : CVE-2025-2402

CVE.ORG link : CVE-2025-2402


JSON object : View

Products Affected

knime

  • business_hub
CWE
CWE-259

Use of Hard-coded Password