CVE-2025-22612

CVSS 3.1 Score 10 of 10 (high)

Details

Published Jan 24, 2025
CWE ID 862
CWE ID 200

Summary

CVE-2025-22612 is a vulnerability affecting the open-source Coolify tool, used for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the software lacked sufficient authorization checks, enabling authenticated users to retrieve any existing private keys in plain text. If an attacker's server configuration matches the victim's (IP/domain, port, and user, often with root access), they can execute arbitrary commands on the remote server, potentially leading to significant security compromises. The vulnerability is addressed in version 4.0.0-beta.374 through proper authorization checks and key handling improvements.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share