Information Disclosure in Cosmos Home Server by Azukaar
CVE-2025-23214
6.9MEDIUM
What is CVE-2025-23214?
The Cosmos server by Azukaar allows users to self-host their applications securely; however, a flaw exists in its login system. By monitoring specific error codes, an attacker could determine the existence of user accounts within the database. This issue can potentially lead to unauthorized access or further exploitation. It is essential for users to upgrade to version 0.17.7 or later to mitigate this risk.
Affected Version(s)
Cosmos-Server < 0.17.7
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
