Impact
The vulnerability arises from weak encoding of log drain secret and environment values that are directly interpolated into shell commands. An attacker with authenticated access can modify these values to inject arbitrary shell commands, which are then executed on the host machine, giving the attacker full control over the environment and compromising confidentiality, integrity, and availability of the host and its services.
Affected Systems
The affected product is Coolify, released by coollabsio. Any installation of Coolify older than version 4.0.0-beta.466 is vulnerable. No other vendors or products are impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 8 high severity. While the EPSS score is below 1% suggesting a low likelihood of exploitation, the CVE description shows that an authenticated user can alter log drain secrets or environment values used in shell commands. Based on this description, the likely attack vector involves injection of shell commands via those values, which could give the attacker full host control. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment