Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to fetch the global coolify instance OAuth configuration. This exposes the "client id" and "client secret" for every custom OAuth provider. The attacker can also modify the global OAuth configuration. Version 4.0.0-beta.361 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 24 Jan 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 24 Jan 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to fetch the global coolify instance OAuth configuration. This exposes the "client id" and "client secret" for every custom OAuth provider. The attacker can also modify the global OAuth configuration. Version 4.0.0-beta.361 fixes the issue. | |
Title | Coolify Vulnerable to OAuth Secrets Leak | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-01-24T16:33:17.058Z
Updated: 2025-01-24T21:30:24.874Z
Reserved: 2025-01-07T15:07:26.776Z
Link: CVE-2025-22610

Updated: 2025-01-24T21:29:46.044Z

Status : Received
Published: 2025-01-24T17:15:15.237
Modified: 2025-01-24T17:15:15.237
Link: CVE-2025-22610

No data.