Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-53374


Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated low-privileged account can retrieve detailed profile information about another users in the same organization by directly invoking user.one. The response discloses personally-identifiable information (PII) such as e-mail address, role, two-factor status, organization ID, and various account flags. The fix will be available in the v0.23.7.


Published

2025-07-07T16:15:25.113

Last Modified

2025-07-08T16:18:34.923

Status

Awaiting Analysis

Source

[email protected]

Severity

-

Weaknesses
  • Type: Primary
    CWE-359
    CWE-862

Affected Vendors & Products

-


References