PT-2026-20327 · Cern · Indico

Inkz

+2

·

Publicado

2026-02-17

·

Atualizado

2026-02-26

·

CVE-2026-25738

CVSS v4.0

6.9

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Indico versions prior to 3.3.10
Description Indico, an event management system, is susceptible to server-side request forgery (SSRF). The system makes outgoing requests to URLs provided by users. While this functionality is intentional, it could allow access to sensitive targets like localhost or cloud metadata endpoints. The risk is limited to event organizers who can access endpoints where SSRF could be used to view returned data. Users hosted on AWS without authentication for sensitive data are less affected.
Recommendations Versions prior to 3.3.10 should be upgraded to version 3.3.10. As a preventative measure, set the http proxy and https proxy environment variables on both the indico-uwsgi and indico-celery services to force outgoing requests through a limiting proxy.

Exploit

Correção

SSRF

Time Of Check To Time Of Use

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25738
GHSA-F47C-3C5W-V7P4

Produtos afetados

Indico