Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to revoke any team invitations on a Coolify instance by only providing a predictable and incrementing ID, resulting in a Denial-of-Service attack (DOS). Version 4.0.0-beta.361 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 24 Jan 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to revoke any team invitations on a Coolify instance by only providing a predictable and incrementing ID, resulting in a Denial-of-Service attack (DOS). Version 4.0.0-beta.361 fixes the issue. | |
Title | Coolify Vulnerable to Revocation of Arbitrary Team Invitations (DOS) | |
Weaknesses | CWE-639 CWE-862 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-12T20:01:19.259Z
Reserved: 2025-01-07T15:07:26.776Z
Link: CVE-2025-22608

Updated: 2025-02-12T19:55:48.184Z

Status : Received
Published: 2025-01-24T17:15:14.960
Modified: 2025-01-24T17:15:14.960
Link: CVE-2025-22608

No data.