Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to fetch the details page for any GitHub / GitLab configuration on a Coolify instance by only knowing the UUID of the model. This exposes the "client id", "client secret" and "webhook secret." Version 4.0.0-beta.361 fixes this issue.
Metrics
Affected Vendors & Products
References
History
Fri, 24 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 24 Jan 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to fetch the details page for any GitHub / GitLab configuration on a Coolify instance by only knowing the UUID of the model. This exposes the "client id", "client secret" and "webhook secret." Version 4.0.0-beta.361 fixes this issue. | |
Title | Coolify Vulnerable to GitHub / GitLab OAuth Secrets Leak | |
Weaknesses | CWE-200 CWE-862 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-01-24T15:45:03.711Z
Updated: 2025-01-24T15:58:23.987Z
Reserved: 2025-01-07T15:07:26.775Z
Link: CVE-2025-22607

Updated: 2025-01-24T15:58:09.392Z

Status : Received
Published: 2025-01-24T16:15:38.470
Modified: 2025-01-24T16:15:38.470
Link: CVE-2025-22607

No data.