Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability affects Coolify software, allowing attackers to gain unauthorized access to user accounts by exploiting a weakness in how the system handles external login providers. The issue bypasses standard security measures like passwords and multi-factor authentication if an attacker can link a victim's email address to a compromised or attacker-controlled external account. The main concern is confirming relevance and exposure, as the method of exploitation requires specific conditions.
- Bypasses authentication using external logins.
- Important for preventing unauthorized account access.
- Confirm relevance and exposure for leadership.
Attack Path
How an attacker could exploit the issue
An attacker could gain access to a user's account by exploiting a vulnerability in the OAuth callback handler. This would involve an attacker registering a victim's email address with an OAuth provider and then using that to bypass Coolify's authentication, effectively taking over the user's account.
- Requires attacker to control a victim's email.
- Triggers on OAuth callback with unverified email.
- Enables unauthenticated account takeover.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow attackers to bypass authentication and gain access to user accounts by registering a victim's email address with an OAuth provider. This bypasses password and two-factor authentication requirements when supported by the advisory.
- User accounts could be compromised.
- Attackers could impersonate users via email.
- Unauthorized access to services may occur.
Operational Fix
Recommended remediation, mitigation, and detection steps
The application owner is responsible for addressing this vulnerability, as it impacts the authentication flow within the Coolify platform. The immediate priority is to identify all instances of Coolify, confirm their exposure, and determine business criticality to prioritize remediation efforts.
- Application owners should manage this vulnerability.
- Verify external access and business criticality.
- Plan remediation based on identified risk.