CVE-2025-2402
A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones listed below allows an unauthenticated remote attacker in possession of the password to read and manipulate swapped jobs or read and manipulate in- and output data of active jobs. It is also possible to cause a denial-of-service of most functionality of KNIME Business Hub by writing large amounts of data to the object store directly. There are no viable workarounds therefore we strongly recommend to update to one of the following versions of KNIME Business Hub: * 1.13.2 or later * 1.12.3 or later * 1.11.3 or later * 1.10.3 or later
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:N/AU:Y/R:U/V:C/RE:M/U:Amber
- EPSS probability
- 0.38%
- CWE
- CWE-259
- Published
- 2025-03-31
- Last modified
- 2026-03-12
Affected products
- KNIME KNIME Business Hub
- KNIME KNIME Business Hub
- KNIME KNIME Business Hub
- KNIME KNIME Business Hub
Weakness type
Related vulnerabilities
- CVE-2026-86673 — ningzichun Student Management System Database Connection database.php mysqli_connect hard-coded credentials
- CVE-2026-86276 — SourceCodester Syllabus-Aligned Learning Management & Examination System db.php hard-coded credentials
- CVE-2026-86150 — Tenda CP3 hostapd hard-coded credentials
- CVE-2026-70403 — XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the...
- CVE-2026-82808 — Inbox Foundry ActiveInbox Extension Google OAuth Client Secret service-worker.production-esm.js hard-coded credentials
- CVE-2026-78062 — vas3k TaxHacker JWT Secret config.ts envSchema.parse hard-coded credentials
- CVE-2026-23933 — Hardcoded session key in Zabbix 7.4
- CVE-2026-19901 — LB-LINK X-PRO easycwmp hard-coded credentials