PT-2025-4596 · Coolify · Coolify

Angelej

·

Published

2025-01-24

·

Updated

2025-01-31

·

CVE-2025-22610

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Coolify versions prior to 4.0.0-beta.361
Description The issue is related to missing authorization, allowing any authenticated user to access and modify the global Coolify instance OAuth configuration. This exposes sensitive information, including the client id and client secret for every custom OAuth provider.
Recommendations For versions prior to 4.0.0-beta.361, update to version 4.0.0-beta.361 or later to resolve the issue. As a temporary workaround, consider restricting access to the global OAuth configuration to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-22610
GHSA-496V-9Q38-2X6C

Affected Products

Coolify