Information Disclosure in Cosmos Home Server by Azukaar
CVE-2025-23214

6.9MEDIUM

Key Information:

Vendor

Azukaar

Vendor
CVE Published:
20 January 2025

What is CVE-2025-23214?

The Cosmos server by Azukaar allows users to self-host their applications securely; however, a flaw exists in its login system. By monitoring specific error codes, an attacker could determine the existence of user accounts within the database. This issue can potentially lead to unauthorized access or further exploitation. It is essential for users to upgrade to version 0.17.7 or later to mitigate this risk.

Affected Version(s)

Cosmos-Server < 0.17.7

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-23214 : Information Disclosure in Cosmos Home Server by Azukaar