CVE-2025-31484 - CVE House
Back to Database
Status published Critical CVE-2025-31484

conda-forge infrastructure uses a bad token for Azure's cf-staging access

Vulnerability Description

conda-forge infrastructure holds common configurations and settings for key pieces of the conda-forge infrastructure. Between 2025-02-10 and 2025-04-01, conda-forge infrastructure used the wrong token for Azure's cf-staging access. This bug meant that any feedstock maintainer could upload a package to the conda-forge channel, bypassing our feedstock-token + upload process. The security logs on anaconda.org were check for any packages that were not copied from the cf-staging to the conda-forge channel and none were found.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-31484

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

conda-forge

View all reports →

Affected Software

infrastructure
Vulnerable Versions:
>= 2025-02-10, <= 2025-04-01

Timeline

Official Publish: April 2nd, 2025
Last Modified: April 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)