CVE-2025-22608

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 24, 2025
CWE ID 639
CWE ID 862

Summary

CVE-2025-22608 is a vulnerability affecting Coolify, an open-source tool for managing servers, applications, and databases. Before version 4.0.0-beta.361, the platform suffered from a missing authorization issue, which enabled any authenticated user to revoke team invitations with a predictable and incrementing ID. This vulnerability could lead to a Denial-of-Service (DoS) attack, significantly impacting the availability and functionality of the Coolify instance. The issue has been addressed in version 4.0.0-beta.361.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share