← Zuruck zu CVEs
CVE-2025-56157
CRITICAL9.8
Beschreibung
Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version 1.0.1 or later.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht12/18/2025
Zuletzt geandert1/29/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
langgenius:dify
Schwachen (CWE)
CWE-798
Referenzen
http://dify.com(cve@mitre.org)
https://github.com/langgenius/dify(cve@mitre.org)
https://github.com/langgenius/dify/issues/15285(cve@mitre.org)
https://github.com/langgenius/dify/pull/15286(cve@mitre.org)
https://github.com/langgenius/dify/pull/15286.diff(cve@mitre.org)
https://github.com/langgenius/dify/releases/tag/1.0.1(cve@mitre.org)
https://gist.github.com/Cristliu/216ddbadaf3258498c93d408683ecabd(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.