Beveiligingsadvies

CVE-2025-22608

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-01-24 16:28:51
Laatst bijgewerkt 2025-02-12 20:01:19
Toegewezen door GitHub_M
CVSS-score 6.5
Status PUBLISHED

Beschrijving

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to revoke any team invitations on a Coolify instance by only providing a predictable and incrementing ID, resulting in a Denial-of-Service attack (DOS). Version 4.0.0-beta.361 fixes the issue.