CyberRota Analysis
AI-GeneratedThe vulnerability allows an attacker to exploit the GET /invitations/{uuid} endpoint in Coolify versions prior to 4.0.0-beta.471 to reset a victim's account password using a known invitation UUID. This can lead to unauthorized access to user accounts, posing a significant risk to user data and application integrity. Organizations using affected versions should prioritize upgrading to the fixed version to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GET /invitations/{uuid} endpoint can perform a state-changing password reset using an attacker-known invitation UUID, allowing an attacker who can cause a victim to visit the crafted invitation URL to reset the victim account password to a predictable value. This issue is fixed in version 4.0.0-beta.471.