Hard-coded password for object store of KNIME Business Hub
Published Mar 31, 2025
8.8
HIGHCVSS 4.0
EPSS 0.39%
Description
A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones listed below allows an unauthenticated remote attacker in possession of the password to read and manipulate swapped jobs or read and manipulate in- and output data of active jobs. It is also possible to cause a denial-of-service of most functionality of KNIME Business Hub by writing large amounts of data to the object store directly.
There are no viable workarounds therefore we strongly recommend to update to one of the following versions of KNIME Business Hub:
* 1.13.2 or later
* 1.12.3 or later
* 1.11.3 or later
* 1.10.3 or later
Affected products
-
Affected
- ≥ 0, < 1.10.3
- ≥ 1.11.0, < 1.11.3
- ≥ 1.12.0, < 1.12.3
- ≥ 1.13.0, < 1.13.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Knime | KNIME Business Hub | unaffected | Affected
|
- < 1.10.3
- ≥ 1.11.0 · < 1.11.3
- ≥ 1.12.0 · < 1.12.3
- ≥ 1.13.0 · < 1.13.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-8704 Advisory
- https://github.com/advisories/GHSA-v5p7-3387-gpmg third-party-advisoryThird Party Advisory
- https://www.knime.com/security/advisories#CVE-2025-2402 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-8704 | Advisory | |
| https://github.com/advisories/GHSA-v5p7-3387-gpmg | third-party-advisoryThird Party Advisory | |
| https://www.knime.com/security/advisories#CVE-2025-2402 | Vendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data