Skip to content

User Information Disclosure via user.one Endpoint

Moderate
Siumauricio published GHSA-fcq8-wv2q-f758 Jul 5, 2025

Package

docker dokploy/dokploy (Docker)

Affected versions

< 0.23.6

Patched versions

0.23.7

Description

Impact

An authenticated low-privileged account, one that does belong to organisation,
can retrieve detailed profile information about another users in the same org users by directly invoking user.one.
The response discloses personally-identifiable information (PII) such as e-mail address,
role, two-factor status, organisation ID, and various account flags

Patches

The fix will be available in the v0.23.7

Severity

Moderate

CVE ID

CVE-2025-53374

Weaknesses

No CWEs

Credits