Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in Coolify, a tool for managing servers and applications, could allow unauthorized command execution. This means a user with limited access could potentially run commands on the system as an administrator. The primary concern is to confirm if this tool is in use and if it is affected.
- Low-privilege users could run commands as root.
- Confirms relevance and exposure for leadership.
- Assess impact and ensure system integrity.
Attack Path
How an attacker could exploit the issue
An attacker with low-privileged access to Coolify can exploit a command injection flaw within the git source input fields. This allows them to execute arbitrary system commands as the root user on the server hosting Coolify, leading to a complete compromise of the instance. It is currently unclear if a patch has been released for this vulnerability.
- Low privileged access is required.
- Git source input fields are the trigger.
- Full system compromise is the risk.
Live Threat
Current exploitation, exposure, and threat context
A command injection vulnerability in Coolify could allow a low-privileged user to execute arbitrary system commands as root on the Coolify instance. This could affect the integrity and availability of the server hosting Coolify, as well as any applications, servers, or databases managed by it.
- System commands could be executed.
- Via git source input fields.
- Compromise of the Coolify instance.
Operational Fix
Recommended remediation, mitigation, and detection steps
The command injection vulnerability in Coolify affects the git source input fields and allows low-privileged users to execute arbitrary commands as root. This impacts users with self-hosted instances of Coolify, potentially exposing the entire Coolify instance and its managed resources. The first practical step is to identify all Coolify instances, confirm their reachability and criticality, and locate the responsible owner for remediation.
- Determine ownership: Application or platform teams.
- Verify: Identify and confirm reachability and criticality.
- Action: Plan remediation or implement controls.