PT-2025-4593 · Coolify · Coolify

Angelej

·

Published

2025-01-24

·

Updated

2025-01-24

·

CVE-2025-22607

CVSS v4.0

5.7

Medium

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Coolify versions prior to 4.0.0-beta.361
Description The issue is related to missing authorization in Coolify, allowing any authenticated user to access sensitive information, including client id, client secret, and webhook secret, for any GitHub or GitLab configuration by knowing the UUID of the model.
Recommendations For versions prior to 4.0.0-beta.361, update to version 4.0.0-beta.361 or later to resolve the issue. As a temporary workaround, consider restricting access to the GitHub and GitLab configuration details page to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-22607
GHSA-8W24-GFGQ-JG72

Affected Products

Coolify