CVE-2025-2402 describes a critical vulnerability in KNIME Business Hub, affecting all versions except 1.13.2+, 1.12.3+, 1.11.3+, and 1.10.3+. This flaw stems from a hard-coded, non-random password for the MinIO object store. An unauthenticated remote attacker can exploit this to read and manipulate sensitive data, including swapped jobs and active job inputs/outputs, or cause a denial-of-service by overwhelming the object store. The vulnerability carries a CVSS score of 8.6 (HIGH), indicating a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. There are no viable workarounds, necessitating an immediate update to a patched version. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, which is typical for the majority of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.10.3CPE matchmatch criteria | cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:* | ||
>= 1.11.0, < 1.11.3CPE matchmatch criteria | cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:* | ||
>= 1.12.0, < 1.12.3CPE matchmatch criteria | cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:* | ||
>= 1.13.0, < 1.13.2CPE matchmatch criteria | cpe:2.3:a:knime:business_hub:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.