You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
andrasbacsai
published
GHSA-8w24-gfgq-jg72Jan 24, 2025
Package
coolify
(coollabsio)
Affected versions
< v4.0.0-beta.361
Patched versions
v4.0.0-beta.361
Description
The missing authorization allows any authenticated user to fetch the details page for any GitHub / GitLab configuration on a coolify instance by only knowing the UUID of the model.
This exposes the "client id", "client secret" and "webhook secret"
The missing authorization allows any authenticated user to fetch the details page for any GitHub / GitLab configuration on a coolify instance by only knowing the UUID of the model.
This exposes the "client id", "client secret" and "webhook secret"
PoC