CVE-2025-11239 LOW

CVE-2025-11239: Job details are visible to all team members on KNIME Business Hub

Vendor Knime
Product KNIME Business Hub
Weakness CWE-863 · Incorrect authorization
Published October 2, 2025
Last update October 2, 2025

CVSS base score

2.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/U:Green

What the vulnerability does

01Description

Potentially sensitive information in jobs on KNIME Business Hub prior to 1.16.0 were visible to all members of the user's team. Starting with KNIME Business Hub 1.16.0 only metadata of jobs is shown to team members. Only the creator of a job can see all information including in- and output data (if present).

Key dates

02Disclosure timeline

October 2, 2025 CVE published
October 2, 2025 Record updated