You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
andrasbacsai
published
GHSA-qmxm-wvm9-wvxxJan 24, 2025
Package
coolify
(coollabsio)
Affected versions
< v4.0.0-beta.361
Patched versions
v4.0.0-beta.361
Description
The missing authorization allows any authenticated user to revoke any team invitations on a coolify instance by only providing a predictable and incrementing ID, resulting in a Denial-of-Service attack (DOS).
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Learn more on MITRE.
The missing authorization allows any authenticated user to revoke any team invitations on a coolify instance by only providing a predictable and incrementing ID, resulting in a Denial-of-Service attack (DOS).
PoC