Goal Reached Thanks to every supporter β€” we hit 100%!

Goal: 1000 CNY Β· Raised: 1000 CNY

100.0%

CVE-2025-22612 β€” AI Deep Analysis Summary

CVSS 10.0 Β· Critical

Q1What is this vulnerability? (Essence + Consequences)

🚨 **Essence**: Coolify < 4.0.0-beta.374 leaks private keys in **plaintext**. <br>πŸ“‰ **Consequences**: Total compromise of infrastructure security. Attackers gain full access to sensitive credentials.…

Q2Root Cause? (CWE/Flaw)

πŸ›‘οΈ **Root Cause**: **Missing Authorization** check. <br>πŸ” **CWE**: CWE-200 (Information Exposure). <br>❌ **Flaw**: No access control on key retrieval endpoints. Any authenticated user can bypass security layers. πŸ›‘οΈ

Q3Who is affected? (Versions/Components)

πŸ‘₯ **Affected**: **Coolify** (Self-hosted PaaS). <br>πŸ“¦ **Version**: All versions **before 4.0.0-beta.374**. <br>🏒 **Vendor**: coollabsio. <br>⚠️ **Scope**: Users running older beta or stable builds. πŸ‘₯

Q4What can hackers do? (Privileges/Data)

πŸ’» **Hackers Can**: Retrieve **ANY** existing private key. <br>πŸ”“ **Privileges**: Acts as an authenticated user. <br>πŸ“‚ **Data**: Accesses instance secrets in **plaintext**.…

Q5Is exploitation threshold high? (Auth/Config)

βš–οΈ **Threshold**: **LOW**. <br>πŸ”‘ **Auth**: Requires **Authentication**. <br>βš™οΈ **Config**: No special config needed. <br>🎯 **Ease**: Simple API call if logged in. Not zero-day. βš–οΈ

Q6Is there a public Exp? (PoC/Wild Exploitation)

🌐 **Public Exp?**: **No PoC** listed. <br>πŸ“œ **Status**: Advisory published. <br>πŸ”₯ **Wild Exp**: Unlikely yet. <br>πŸ‘€ **Watch**: Monitor GitHub advisories for proof-of-concept releases. 🌐

Q7How to self-check? (Features/Scanning)

πŸ” **Self-Check**: Scan for Coolify instances. <br>πŸ“Š **Version**: Verify version < 4.0.0-beta.374. <br>πŸ•΅οΈ **Test**: Try accessing key endpoints with valid creds. <br>πŸ› οΈ **Tools**: Use DAST scanners for auth bypass. πŸ”

Q8Is it fixed officially? (Patch/Mitigation)

βœ… **Fixed**: **Yes**. <br>πŸ”§ **Patch**: Upgrade to **4.0.0-beta.374** or later. <br>πŸ“₯ **Source**: GitHub Security Advisory (GHSA-wg8x-cgq4-vjxj). <br>πŸ”„ **Action**: Immediate update required. βœ…

Q9What if no patch? (Workaround)

🚧 **No Patch?**: Rotate all private keys immediately. <br>πŸ”’ **Mitigation**: Restrict user access levels. <br>πŸ›‘ **Block**: Disable key retrieval endpoints if possible.…

Q10Is it urgent? (Priority Suggestion)

πŸ”₯ **Urgency**: **HIGH**. <br>🚨 **Priority**: Patch ASAP. <br>⚠️ **Risk**: CVSS High (C:H, I:H, A:H). <br>πŸ“’ **Action**: Critical security update. Do not delay. πŸ”₯